An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | debian-upgrade-libstbno-fix-debian-deb-package | Feb 2, 2023 | Oct 21, 2021 | |
| Gentoo Linux | gentoo-linux-upgrade-dev-libs-stb | Sep 23, 2024 | Oct 21, 2021 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Oct 21, 2021 |
| Suse | — | suse-upgrade-libzxing1suse-upgrade-zxing-cpp-devel | Jan 25, 2022 | Oct 21, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub