CVE-2025-0459

NameCVE-2025-0459
DescriptionA vulnerability, which was classified as problematic, has been found in libretro RetroArch up to 1.19.1 on Windows. Affected by this issue is some unknown functionality in the library profapi.dll of the component Startup. The manipulation leads to untrusted search path. An attack has to be approached locally. The vendor was contacted early about this disclosure but did not respond in any way.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
retroarch (PTS)bullseye1.7.3+dfsg1-1.1fixed
bookworm1.14.0+dfsg-1fixed
trixie1.19.1+dfsg-1fixed
sid1.20.0+dfsg-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
retroarchsource(unstable)(not affected)

Notes

- retroarch <not-affected> (Windows-specific)

Search for package or bug name: Reporting problems