CVE-2025-3408

NameCVE-2025-3408
DescriptionA vulnerability was found in Nothings stb up to f056911. It has been rated as critical. Affected by this issue is the function stb_dupreplace. The manipulation leads to integer overflow. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1103632

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
libstb (PTS)bullseye0.0~git20200713.b42009b+ds-1vulnerable
bookworm0.0~git20220908.8b5f1f3+ds-1vulnerable
sid, trixie0.0~git20241109.5c20573+ds-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libstbsource(unstable)(unfixed)1103632

Notes

[bookworm] - libstb <no-dsa> (Minor issue)
[bullseye] - libstb <postponed> (Minor issue)
https://github.com/nothings/stb/issues/1770

Search for package or bug name: Reporting problems