CVE-2025-2177

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Mar 11, 2025
CWE ID 476

Summary

CVE-2025-2177 is a critical vulnerability affecting libzvbi up to version 0.2.43. The issue lies in the vbi_search_new function of the file src/search.c, where manipulation of the argument pat_len results in integer overflow. This vulnerability can be exploited remotely, and the exploit has already been disclosed to the public. To mitigate the risk, it is recommended to upgrade to version 0.2.44, which contains the patch identified as ca1672134b3e2962cd392212c73f44f8f4cb489f. The code maintainer was informed of the issue and responded promptly and professionally.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share