Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-6199— Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder

Quick assessment

Affected
CVE-2025-6199
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GdkPixBuf是一款支持加载多种格式图像文件的库。 GdkPixBuf存在信息泄露漏洞,该漏洞源于GIF解析器中LZW解码器处理无效符号不当,可能导致内存内容泄露。

CVSS 3.3 · Low EPSS 0.20% · P11

Possible ATT&CK Techniques 1 AI

T1005 · Data from Local System

Affected Version Matrix 10

VendorProduct Version RangeStatus
None None < 2.43.2 affected
Red Hat Red Hat Enterprise Linux 10 any affected
any affected
any affected
any affected
Red Hat Red Hat Enterprise Linux 6 any unknown
Red Hat Red Hat Enterprise Linux 7 any affected
Red Hat Red Hat Enterprise Linux 8 any affected
Red Hat Red Hat Enterprise Linux 9 any affected
any affected

I. Basic Information for CVE-2025-6199

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Gdk-pixbuf: uninitialized memory disclosure in gdkpixbuf gif lzw decoder
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in the GIF parser of GdkPixbuf’s LZW decoder. When an invalid symbol is encountered during decompression, the decoder sets the reported output size to the full buffer length rather than the actual number of written bytes. This logic error results in uninitialized sections of the buffer being included in the output, potentially leaking arbitrary memory contents in the processed image.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
信息暴露
Source: CVE Program / CVE List V5
Vulnerability Title
GdkPixBuf 信息泄露漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GdkPixBuf是一款支持加载多种格式图像文件的库。 GdkPixBuf存在信息泄露漏洞,该漏洞源于GIF解析器中LZW解码器处理无效符号不当,可能导致内存内容泄露。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- - 0 ~ 2.43.2 -
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2025-6199

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-6199

登录查看更多情报信息。

Vendor Advisories for CVE-2025-6199 (1)

Other References for CVE-2025-6199 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2025-6199

No comments yet


Leave a comment