CVE-2025-53644

EUVD-2025-21795
OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 21%
Affected Products (NVD)
VendorProductVersion
opencvopencv
4.10.0 ≤
𝑥
< 4.12.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
opencv
bookworm
4.6.0+dfsg-12
fixed
bullseye
4.5.1+dfsg-5
fixed
forky
4.10.0+dfsg-7
fixed
sid
4.10.0+dfsg-7
fixed
trixie
4.10.0+dfsg-5
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
opencv
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
plucky
not-affected
trusty
not-affected
xenial
not-affected