CVE-2025-6199

A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2025-6199 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2373147 Issue Tracking Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:gnome:gdkpixbuf:2.0.0:-:*:*:*:*:*:*
OR cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

21 Aug 2025, 01:16

Type Values Removed Values Added
Summary
  • (es) Se detectó una falla en el analizador GIF del decodificador LZW de GdkPixbuf. Al encontrar un símbolo no válido durante la descompresión, el decodificador establece el tamaño de salida reportado en la longitud total del búfer, en lugar del número real de bytes escritos. Este error lógico provoca que se incluyan secciones no inicializadas del búfer en la salida, lo que podría provocar la pérdida de contenido de memoria arbitrario en la imagen procesada.
CPE cpe:2.3:o:redhat:enterprise_linux:7.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:9.0:*:*:*:*:*:*:*
cpe:2.3:a:gnome:gdkpixbuf:2.0.0:-:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2025-6199 - () https://access.redhat.com/security/cve/CVE-2025-6199 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2373147 - () https://bugzilla.redhat.com/show_bug.cgi?id=2373147 - Issue Tracking, Third Party Advisory
CWE NVD-CWE-noinfo
First Time Redhat enterprise Linux
Gnome
Redhat
Gnome gdkpixbuf

17 Jun 2025, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 15:15

Updated : 2025-08-21 01:16


NVD link : CVE-2025-6199

Mitre link : CVE-2025-6199

CVE.ORG link : CVE-2025-6199


JSON object : View

Products Affected

gnome

  • gdkpixbuf

redhat

  • enterprise_linux
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

NVD-CWE-noinfo