CVE-2025-53644

OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
GitHub_MCNA
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 16%
VendorProductVersion
opencvopencv
4.10.0 ≤
𝑥
< 4.12.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
opencv
bullseye
4.5.1+dfsg-5
fixed
bookworm
4.6.0+dfsg-12
fixed
trixie
4.10.0+dfsg-5
fixed
forky
4.10.0+dfsg-6
fixed
sid
4.10.0+dfsg-6
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
opencv
plucky
not-affected
noble
not-affected
jammy
not-affected
focal
not-affected
bionic
not-affected
xenial
not-affected
trusty
not-affected