CVE-2025-29070

EUVD-2025-9489
A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 55%
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lcms2
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
oracular
not-affected
plucky
not-affected
trusty
not-affected
xenial
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
lcms2
Amazon Linux 2
0:2.6-3.amzn2.0.3
fixed
Amazon Linux 2023
0:2.16-74.amzn2023
fixed
lcms2-debuginfo
Amazon Linux 2
0:2.6-3.amzn2.0.3
fixed
Amazon Linux 2023
0:2.16-74.amzn2023
fixed
lcms2-debugsource
Amazon Linux 2023
0:2.16-74.amzn2023
fixed
lcms2-devel
Amazon Linux 2
0:2.6-3.amzn2.0.3
fixed
Amazon Linux 2023
0:2.16-74.amzn2023
fixed
lcms2-utils
Amazon Linux 2
0:2.6-3.amzn2.0.3
fixed
Amazon Linux 2023
0:2.16-74.amzn2023
fixed
lcms2-utils-debuginfo
Amazon Linux 2023
0:2.16-74.amzn2023
fixed