CVE-2025-6199

NameCVE-2025-6199
DescriptionA flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4225-1, DSA-5946-1
Debian Bugs1107994

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
gdk-pixbuf (PTS)bullseye2.42.2+dfsg-1+deb11u2vulnerable
bullseye (security)2.42.2+dfsg-1+deb11u3fixed
bookworm2.42.10+dfsg-1+deb12u1vulnerable
bookworm (security)2.42.10+dfsg-1+deb12u2fixed
sid, trixie2.42.12+dfsg-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
gdk-pixbufsourcebullseye2.42.2+dfsg-1+deb11u3DLA-4225-1
gdk-pixbufsourcebookworm2.42.10+dfsg-1+deb12u2DSA-5946-1
gdk-pixbufsource(unstable)2.42.12+dfsg-31107994

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=2373147
https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/257
https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/191
Fixed by: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/c4986342b241cdc075259565f3fa7a7597d32a32 (2.43.2)

Search for package or bug name: Reporting problems
OSZAR »