Advisories ยป MGASA-2025-0257

Updated libavif packages fix security vulnerabilities

Publication date: 04 Nov 2025
Modification date: 04 Nov 2025
Type: security
Affected Mageia releases : 9
CVE: CVE-2025-48174 , CVE-2025-48175

Description

In libavif before 1.3.0, makeRoom in stream.c has an integer overflow
and resultant buffer overflow in stream->offset+size. (CVE-2025-48174)
In libavif before 1.3.0, avifImageRGBToYUV in reformat.c has integer
overflows in multiplications involving rgbRowBytes, yRowBytes,
uRowBytes, and vRowBytes. (CVE-2025-48175)
                

References

SRPMS

9/core