CVE-2025-20889

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Feb 4, 2025
Updated: Feb 12, 2025
CWE ID 787

Summary

CVE-2025-20889 is a vulnerability affecting libsthmbc.so's smp4vtd decoder before the SMR Jan-2025 Release 1. This issue involves an out-of-bounds read, which can be exploited by local attackers who manage to feed malformed bitstreams to the decoder. The attacker can then read arbitrary memory on the system, requiring user interaction to trigger the vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share