• CVE-2025-6199

发布时间: 2025年7月18日

修改时间: 2025年7月18日

概要

A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.

CVSS v3 指标

NVD openEuler
Confidentiality Low Low
Attack Vector Local Local
CVSS评分 3.3 3.3
Attack Complexity Low Low
Privileges Required None None
Scope Unchanged Unchanged
Integrity None None
User Interaction Required Required
Availability None None

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2758 gdk-pixbuf2 security update 2025年7月25日

影响产品

产品 状态
KY3.4-5A gdk-pixbuf2 Fixed
KY3.5.3 gdk-pixbuf2 Fixed
V6 gdk-pixbuf2 Fixed
KY3.5.2 gdk-pixbuf2 Fixed