Back to Database
Status published
Medium
CVE-2025-48174
In libavif before 1.3.0, makeRoom in stream.c has an integer...
Vulnerability Description
In libavif before 1.3.0, makeRoom in stream.c has an integer overflow and resultant buffer overflow in stream->offset+size.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-48174
Credits & Attribution
No credits recorded in the NVD database.
References
- https://github.com/AOMediaCodec/libavif/pull/2768
- https://github.com/AOMediaCodec/libavif/commit/e5fdefe7d1776e6c4cf1703c163a8c0535599029
- https://github.com/AOMediaCodec/libavif/commit/50a743062938a3828581d725facc9c2b92a1d109
- https://github.com/AOMediaCodec/libavif/commit/c9f1bea437f21cb78f9919c332922a3b0ba65e11
More from aomedia
View All →CVE-2025-48175
In libavif before 1.3.0, avifImageRGBToYUV in reformat.c has integer overflows...
Medium
4.5
CVE-2021-30475
aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer...
Critical
9.8
CVE-2021-30474
aom_dsp/grain_table.c in libaom in AOMedia before 2021-03-30 has a use-after-free....
Critical
9.8
CVE-2021-30473
aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that...
Critical
9.8
CVE-2020-36407
libavif 0.8.0 and 0.8.1 has an out-of-bounds write in avifDecoderDataFillImageGrid....
High
8.8
Affected Vendor
aomedia
View all reports →Affected Software
libavif
Vulnerable Versions:
0
Timeline
Official Publish:
May 16th, 2025
Last Modified:
November 3rd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:L