CVE-2025-7345

EUVD-2025-20502
A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially causing application crashes or arbitrary code execution.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 76%
Debian logo
Debian Releases
Debian Product
Codename
gdk-pixbuf
bookworm
2.42.10+dfsg-1+deb12u4
fixed
bookworm (security)
2.42.10+dfsg-1+deb12u4
fixed
bullseye
vulnerable
bullseye (security)
2.42.2+dfsg-1+deb11u5
fixed
forky
2.44.6+dfsg-2
fixed
sid
2.44.6+dfsg-2
fixed
trixie
2.42.12+dfsg-4+deb13u1
fixed
trixie (security)
2.42.12+dfsg-4+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
gdk-pixbuf
bionic
Fixed 2.36.11-2ubuntu0.1~esm2
released
focal
Fixed 2.40.0+dfsg-3ubuntu0.5+esm1
released
jammy
Fixed 2.42.8+dfsg-1ubuntu0.4
released
noble
Fixed 2.42.10+dfsg-3ubuntu3.2
released
oracular
ignored
plucky
Fixed 2.42.12+dfsg-2ubuntu0.1
released
questing
Fixed 2.42.12+dfsg-4build1
released
resolute
Fixed 2.42.12+dfsg-4build1
released
xenial
Fixed 2.32.2-1ubuntu1.6+esm2
released
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
gdk-pixbuf-devel
suse enterprise desktop 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise desktop 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise server 12 SP5
2.34.0-19.23.1
fixed
suse enterprise server 15 SP2
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP3
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise server 15 SP7
2.42.12-150600.3.8.1
fixed
gdk-pixbuf-lang
suse enterprise desktop 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise desktop 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise server 12 SP3
2.34.0-19.23.1
fixed
suse enterprise server 12 SP5
2.34.0-19.23.1
fixed
suse enterprise server 15 SP2
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP3
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise server 15 SP7
2.42.12-150600.3.8.1
fixed
gdk-pixbuf-query-loaders
suse enterprise desktop 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise desktop 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise server 12 SP3
2.34.0-19.23.1
fixed
suse enterprise server 12 SP5
2.34.0-19.23.1
fixed
suse enterprise server 15 SP2
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP3
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise server 15 SP7
2.42.12-150600.3.8.1
fixed
gdk-pixbuf-query-loaders-32bit
suse enterprise desktop 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise desktop 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise server 12 SP3
2.34.0-19.23.1
fixed
suse enterprise server 12 SP5
2.34.0-19.23.1
fixed
suse enterprise server 15 SP2
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP3
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise server 15 SP7
2.42.12-150600.3.8.1
fixed
gdk-pixbuf-thumbnailer
suse enterprise desktop 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise desktop 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise server 15 SP2
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP3
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise server 15 SP7
2.42.12-150600.3.8.1
fixed
libgdk_pixbuf-2_0-0
suse enterprise desktop 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise desktop 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise server 12 SP3
2.34.0-19.23.1
fixed
suse enterprise server 12 SP5
2.34.0-19.23.1
fixed
suse enterprise server 15 SP2
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP3
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise server 15 SP7
2.42.12-150600.3.8.1
fixed
libgdk_pixbuf-2_0-0-32bit
suse enterprise desktop 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise desktop 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise server 12 SP3
2.34.0-19.23.1
fixed
suse enterprise server 12 SP5
2.34.0-19.23.1
fixed
suse enterprise server 15 SP2
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP3
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise server 15 SP7
2.42.12-150600.3.8.1
fixed
typelib-1_0-GdkPixbuf-2_0
suse enterprise desktop 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise desktop 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise server 12 SP3
2.34.0-19.23.1
fixed
suse enterprise server 12 SP5
2.34.0-19.23.1
fixed
suse enterprise server 15 SP2
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP3
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise server 15 SP7
2.42.12-150600.3.8.1
fixed
typelib-1_0-GdkPixdata-2_0
suse enterprise desktop 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise desktop 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise sap 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise sap 15 SP7
2.42.12-150600.3.8.1
fixed
suse enterprise server 15 SP2
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP3
2.40.0-150200.3.15.2
fixed
suse enterprise server 15 SP4
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP5
2.42.12-150400.5.14.1
fixed
suse enterprise server 15 SP6
2.42.12-150600.3.8.1
fixed
suse enterprise server 15 SP7
2.42.12-150600.3.8.1
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
gdk-pixbuf2
RHEL 8
0:2.36.12-7.el8_10
fixed
RHEL 8.2 AUS
0:2.36.12-6.el8_2
fixed
RHEL 8.4 AUS
0:2.36.12-6.el8_4
fixed
RHEL 8.6 AUS
0:2.36.12-6.el8_6
fixed
RHEL 8.6 E4S
0:2.36.12-6.el8_6
fixed
RHEL 8.6 TUS
0:2.36.12-6.el8_6
fixed
RHEL 8.8 E4S
0:2.36.12-6.el8_8
fixed
RHEL 8.8 TUS
0:2.36.12-6.el8_8
fixed
RHEL 9
0:2.42.6-6.el9_6
fixed
gdk-pixbuf2-devel
RHEL 8
0:2.36.12-7.el8_10
fixed
RHEL 8.2 AUS
0:2.36.12-6.el8_2
fixed
RHEL 8.4 AUS
0:2.36.12-6.el8_4
fixed
RHEL 8.6 AUS
0:2.36.12-6.el8_6
fixed
RHEL 8.6 E4S
0:2.36.12-6.el8_6
fixed
RHEL 8.6 TUS
0:2.36.12-6.el8_6
fixed
RHEL 8.8 E4S
0:2.36.12-6.el8_8
fixed
RHEL 8.8 TUS
0:2.36.12-6.el8_8
fixed
RHEL 9
0:2.42.6-6.el9_6
fixed
gdk-pixbuf2-modules
RHEL 8
0:2.36.12-7.el8_10
fixed
RHEL 8.2 AUS
0:2.36.12-6.el8_2
fixed
RHEL 8.4 AUS
0:2.36.12-6.el8_4
fixed
RHEL 8.6 AUS
0:2.36.12-6.el8_6
fixed
RHEL 8.6 E4S
0:2.36.12-6.el8_6
fixed
RHEL 8.6 TUS
0:2.36.12-6.el8_6
fixed
RHEL 8.8 E4S
0:2.36.12-6.el8_8
fixed
RHEL 8.8 TUS
0:2.36.12-6.el8_8
fixed
RHEL 9
0:2.42.6-6.el9_6
fixed
gdk-pixbuf2-xlib
RHEL 8
0:2.36.12-7.el8_10
fixed
gdk-pixbuf2-xlib-devel
RHEL 8
0:2.36.12-7.el8_10
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
gdk-pixbuf2
Amazon Linux 2
0:2.36.12-3.amzn2.0.2
fixed
Amazon Linux 2023
0:2.42.12-185.amzn2023
fixed
gdk-pixbuf2-debuginfo
Amazon Linux 2
0:2.36.12-3.amzn2.0.2
fixed
Amazon Linux 2023
0:2.42.12-185.amzn2023
fixed
gdk-pixbuf2-debugsource
Amazon Linux 2023
0:2.42.12-185.amzn2023
fixed
gdk-pixbuf2-devel
Amazon Linux 2
0:2.36.12-3.amzn2.0.2
fixed
Amazon Linux 2023
0:2.42.12-185.amzn2023
fixed
gdk-pixbuf2-devel-debuginfo
Amazon Linux 2023
0:2.42.12-185.amzn2023
fixed
gdk-pixbuf2-modules
Amazon Linux 2023
0:2.42.12-185.amzn2023
fixed
gdk-pixbuf2-modules-debuginfo
Amazon Linux 2023
0:2.42.12-185.amzn2023
fixed
gdk-pixbuf2-tests
Amazon Linux 2
0:2.36.12-3.amzn2.0.2
fixed
Amazon Linux 2023
0:2.42.12-185.amzn2023
fixed
gdk-pixbuf2-tests-debuginfo
Amazon Linux 2023
0:2.42.12-185.amzn2023
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
gdk-pixbuf2
Azure Linux 3.0
0:2.42.10-4.azl3
fixed
CBL-Mariner 2.0
0:2.40.0-8.cm2
fixed