CVE-2025-29070

EUVD-2025-9489
A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 58.49%
Debian logo
Debian Releases
Debian Product
Codename
lcms2
bookworm
unimportant
bookworm (security)
unimportant
bullseye
unimportant
bullseye (security)
unimportant
forky
unimportant
sid
unimportant
trixie
unimportant
trixie (security)
unimportant
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
lcms2
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
oracular
not-affected
plucky
not-affected
trusty
not-affected
xenial
not-affected
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
lcms2
Amazon Linux 2
0:2.6-3.amzn2.0.3
fixed
Amazon Linux 2023
0:2.16-74.amzn2023
fixed
lcms2-debuginfo
Amazon Linux 2
0:2.6-3.amzn2.0.3
fixed
Amazon Linux 2023
0:2.16-74.amzn2023
fixed
lcms2-debugsource
Amazon Linux 2023
0:2.16-74.amzn2023
fixed
lcms2-devel
Amazon Linux 2
0:2.6-3.amzn2.0.3
fixed
Amazon Linux 2023
0:2.16-74.amzn2023
fixed
lcms2-utils
Amazon Linux 2
0:2.6-3.amzn2.0.3
fixed
Amazon Linux 2023
0:2.16-74.amzn2023
fixed
lcms2-utils-debuginfo
Amazon Linux 2023
0:2.16-74.amzn2023
fixed