CVE-2025-3406

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Apr 8, 2025
CWE ID 125
CWE ID 119

Summary

CVE-2025-3406 is a newly discovered vulnerability affecting Nothings stb up to f056911. This issue is considered problematic and impacts the Header Array Handler's stbhw_build_tileset_from_image function. The flaw arises when the argument w is manipulated, resulting in an out-of-bounds read. This vulnerability can be exploited remotely. Noting that this product utilizes a rolling release for continuous delivery, no specific version details regarding affected or updated releases have been disclosed. Despite early contact regarding this disclosure, the vendor has yet to respond.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share