CVE-2025-29069
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Apr 1, 2025
Updated: Apr 4, 2025
CWE ID 122
Summary
CVE-2025-29069 is a newly identified heap buffer overflow vulnerability. The affected component is the lcms2-2.16 library, specifically the UnrollChunkyBytes function in cmspack.c, which handles color space transformations. The issue arises due to improper handling of input data in this function. However, it's important to note that the supplier disputes this finding, asserting that the issue resides in a third-party calling program, not within the lcms library itself.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- lcms2