Logic Error in GdkPixbuf’s GIF Decoder Leading to Memory Leakage
CVE-2025-6199

3.3LOW

Key Information:

What is CVE-2025-6199?

A flaw in the GIF parser of GdkPixbuf’s LZW decoder leads to a logic error when handling invalid symbols during decompression. Instead of reporting the correct number of bytes written, the decoder mistakenly sets the output size to the full buffer length. This oversight can result in uninitialized portions of the buffer being incorporated into the output, which poses a risk of leaking arbitrary memory contents from processed images. This vulnerability can expose sensitive data and requires immediate attention to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.