CVE-2025-53644

NameCVE-2025-53644
DescriptionOpenCV is an Open Source Computer Vision Library. Versions prior to 4.12.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
opencv (PTS)bullseye4.5.1+dfsg-5fixed
bookworm4.6.0+dfsg-12fixed
sid, trixie4.10.0+dfsg-5fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
opencvsource(unstable)3.2.0+dfsg-1

Notes

https://securitylab.github.com/advisories/GHSL-2025-057_OpenCV/
https://github.com/opencv/opencv/issues/27271
Fixed by: https://github.com/opencv/opencv/commit/a39db41390de546d18962ee1278bd6dbb715f466 (4.12.0)
Since opencv/3.1.0+dfsg1-1~exp1 the embedded openjpeg2 copy is excluded
completely via Files-Excluded.

Search for package or bug name: Reporting problems