An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service using stb_image, or read up to 1024 bytes of non-consecutive heap data without control over the read location.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade libstbNo solution exists | May 15, 2025 | Oct 21, 2021 |
| Gentoo Linux | — | Upgrade dev-libs/stb. | Sep 23, 2024 | Oct 21, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Oct 21, 2021 |
| Suse | — | Upgrade stb-develUpgrade zxing-cpp-develUpgrade libzxing1 | Jan 22, 2022 | Oct 21, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub