CVE 6.6 MEDIUM

OpenCV contains a use after free buffer write due to an uninitialized pointer_CVE-2025-53644

6.6 / 10
MEDIUM
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P

Description

OpenCV is an Open Source Computer Vision Library. Versions prior to 4.12.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.

Basic Information

ID CVE-2025-53644
Source GitHub_M
Published Jul 17, 2025 at 17:58
Modified Aug 5, 2025 at 18:37

Affected Product

Vendor opencv
Product opencv
Version < 4.12.0
Affected Versions opencv opencv < 4.12.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.