libzvbi search.c vbi_search_new integer overflow
Published Mar 11, 2025
6.9
MEDIUMCVSS 4.0
EPSS 0.64%
Description
A vulnerability classified as critical was found in libzvbi up to 0.2.43. This vulnerability affects the function vbi_search_new of the file src/search.c. The manipulation of the argument pat_len leads to integer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 0.2.44 is able to address this issue. The patch is identified as ca1672134b3e2962cd392212c73f44f8f4cb489f. It is recommended to upgrade the affected component. The code maintainer was informed beforehand about the issues. She reacted very fast and highly professional.
Affected products
- Vendor n/a Product Libzvbi Defaultunknown
Affected
- 0.2.0
- 0.2.1
- 0.2.10
- 0.2.11
- 0.2.12
- 0.2.13
- 0.2.14
- 0.2.15
- 0.2.16
- 0.2.17
- 0.2.18
- 0.2.19
- 0.2.2
- 0.2.20
- 0.2.21
- 0.2.22
- 0.2.23
- 0.2.24
- 0.2.25
- 0.2.26
- 0.2.27
- 0.2.28
- 0.2.29
- 0.2.3
- 0.2.30
- 0.2.31
- 0.2.32
- 0.2.33
- 0.2.34
- 0.2.35
- 0.2.36
- 0.2.37
- 0.2.38
- 0.2.39
- 0.2.4
- 0.2.40
- 0.2.41
- 0.2.42
- 0.2.43
- 0.2.5
- 0.2.6
- 0.2.7
- 0.2.8
- 0.2.9
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| n/a | Libzvbi | unknown | Affected
|
- < 0.2.44
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-7530 Advisory
- https://github.com/zapping-vbi/zvbi/commit/ca1672134b3e2962cd392212c73f44f8f4cb489f patch
- https://github.com/zapping-vbi/zvbi/releases/tag/v0.2.44 patchRelease Notes
- https://github.com/zapping-vbi/zvbi/security/advisories/GHSA-g7cg-7gw9-v8cf relatedThird Party Advisory
- https://vuldb.com/?ctiid.299206 signaturepermissions-requiredPermissions RequiredVDB Entry
- https://vuldb.com/?id.299206 vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry
- https://vuldb.com/?submit.512803 third-party-advisoryThird Party AdvisoryVDB Entry
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-7530 | Advisory | |
| https://github.com/zapping-vbi/zvbi/commit/ca1672134b3e2962cd392212c73f44f8f4cb489f | patch | |
| https://github.com/zapping-vbi/zvbi/releases/tag/v0.2.44 | patchRelease Notes | |
| https://github.com/zapping-vbi/zvbi/security/advisories/GHSA-g7cg-7gw9-v8cf | relatedThird Party Advisory | |
| https://vuldb.com/?ctiid.299206 | signaturepermissions-requiredPermissions RequiredVDB Entry | |
| https://vuldb.com/?id.299206 | vdb-entrytechnical-descriptionThird Party AdvisoryVDB Entry | |
| https://vuldb.com/?submit.512803 | third-party-advisoryThird Party AdvisoryVDB Entry |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data