Gdk‑pixbuf: heap‑buffer‑overflow in gdk‑pixbuf
Published Jul 8, 2025
7.5
HIGHCVSS 3.1
EPSS 1.25%
Description
A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially causing application crashes or arbitrary code execution.
Affected products
No data.
No data.
No data.
Red Hat Enterprise Linux 10
gdk-pixbuf2-0:2.42.12-4.el10_0
Fixed · RHSA-2025:12862
Red Hat Enterprise Linux 7 Extended Lifecycle Support
gdk-pixbuf2-0:2.36.12-4.el7_9
Fixed · RHSA-2025:14683
Red Hat Enterprise Linux 8
gdk-pixbuf2-0:2.36.12-7.el8_10
Fixed · RHSA-2025:13315
Red Hat Enterprise Linux 8
gdk-pixbuf2-0:2.36.12-7.el8_10
Fixed · RHSA-2025:13315
Red Hat Enterprise Linux 8.2 Advanced Update Support
gdk-pixbuf2-0:2.36.12-6.el8_2
Fixed · RHSA-2025:14618
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
gdk-pixbuf2-0:2.36.12-6.el8_4
Fixed · RHSA-2025:14647
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
gdk-pixbuf2-0:2.36.12-6.el8_4
Fixed · RHSA-2025:14647
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
gdk-pixbuf2-0:2.36.12-6.el8_6
Fixed · RHSA-2025:14646
Red Hat Enterprise Linux 8.6 Telecommunications Update Service
gdk-pixbuf2-0:2.36.12-6.el8_6
Fixed · RHSA-2025:14646
Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions
gdk-pixbuf2-0:2.36.12-6.el8_6
Fixed · RHSA-2025:14646
Red Hat Enterprise Linux 8.8 Telecommunications Update Service
gdk-pixbuf2-0:2.36.12-6.el8_8
Fixed · RHSA-2025:14585
Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
gdk-pixbuf2-0:2.36.12-6.el8_8
Fixed · RHSA-2025:14585
Red Hat Enterprise Linux 9
gdk-pixbuf2-0:2.42.6-6.el9_6
Fixed · RHSA-2025:12841
Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions
gdk-pixbuf2-0:2.42.6-3.el9_0
Fixed · RHSA-2025:14575
Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions
gdk-pixbuf2-0:2.42.6-4.el9_2
Fixed · RHSA-2025:14576
Red Hat Enterprise Linux 9.4 Extended Update Support
gdk-pixbuf2-0:2.42.6-5.el9_4
Fixed · RHSA-2025:14574
Red Hat Enterprise Linux 6
gdk-pixbuf2
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | gdk-pixbuf2-0:2.42.12-4.el10_0 | Fixed | RHSA-2025:12862 |
| Red Hat Enterprise Linux 7 Extended Lifecycle Support | gdk-pixbuf2-0:2.36.12-4.el7_9 | Fixed | RHSA-2025:14683 |
| Red Hat Enterprise Linux 8 | gdk-pixbuf2-0:2.36.12-7.el8_10 | Fixed | RHSA-2025:13315 |
| Red Hat Enterprise Linux 8 | gdk-pixbuf2-0:2.36.12-7.el8_10 | Fixed | RHSA-2025:13315 |
| Red Hat Enterprise Linux 8.2 Advanced Update Support | gdk-pixbuf2-0:2.36.12-6.el8_2 | Fixed | RHSA-2025:14618 |
| Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support | gdk-pixbuf2-0:2.36.12-6.el8_4 | Fixed | RHSA-2025:14647 |
| Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On | gdk-pixbuf2-0:2.36.12-6.el8_4 | Fixed | RHSA-2025:14647 |
| Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support | gdk-pixbuf2-0:2.36.12-6.el8_6 | Fixed | RHSA-2025:14646 |
| Red Hat Enterprise Linux 8.6 Telecommunications Update Service | gdk-pixbuf2-0:2.36.12-6.el8_6 | Fixed | RHSA-2025:14646 |
| Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions | gdk-pixbuf2-0:2.36.12-6.el8_6 | Fixed | RHSA-2025:14646 |
| Red Hat Enterprise Linux 8.8 Telecommunications Update Service | gdk-pixbuf2-0:2.36.12-6.el8_8 | Fixed | RHSA-2025:14585 |
| Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions | gdk-pixbuf2-0:2.36.12-6.el8_8 | Fixed | RHSA-2025:14585 |
| Red Hat Enterprise Linux 9 | gdk-pixbuf2-0:2.42.6-6.el9_6 | Fixed | RHSA-2025:12841 |
| Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions | gdk-pixbuf2-0:2.42.6-3.el9_0 | Fixed | RHSA-2025:14575 |
| Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions | gdk-pixbuf2-0:2.42.6-4.el9_2 | Fixed | RHSA-2025:14576 |
| Red Hat Enterprise Linux 9.4 Extended Update Support | gdk-pixbuf2-0:2.42.6-5.el9_4 | Fixed | RHSA-2025:14574 |
| Red Hat Enterprise Linux 6 | gdk-pixbuf2 | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Vendor solution
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Red Hat statement
The Red Hat Product Security team has rated this vulnerability as Moderate.The flaw, identified in gdk-pixbuf, allows remote attackers to trigger a denial of service by supplying a specially crafted image file. This issue stems from improper bounds handling during image decoding. While exploitable without authentication, it does not lead to data compromise or code execution.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (17)
- https://access.redhat.com/errata/RHSA-2025:12841 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:12862 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:13315 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:14574 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:14575 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:14576 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:14585 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:14618 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:14646 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:14647 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2025:14683 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2025-7345 vdb-entryx_refsource_REDHATVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2377063 issue-trackingx_refsource_REDHATIssue Tracking
- https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/249
- https://lists.debian.org/debian-lts-announce/2025/10/msg00024.html
- https://nvd.nist.gov/vuln/detail/CVE-2025-7345
- https://www.cve.org/CVERecord?id=CVE-2025-7345
Change history (0)
No recorded changes yet.