OpenCV is an Open Source Computer Vision Library. Versions prior to 4.12.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
History

Tue, 05 Aug 2025 18:45:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P'}

cvssV4_0

{'score': 6.6, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P'}


Tue, 05 Aug 2025 14:30:00 +0000

Type Values Removed Values Added
Title GHSL-2025-057 - OpenCV contains a use after free buffer write due to an uninitialized pointer OpenCV contains a use after free buffer write due to an uninitialized pointer

Fri, 18 Jul 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

threat_severity

Important


Thu, 17 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Jul 2025 18:15:00 +0000

Type Values Removed Values Added
Description OpenCV is an Open Source Computer Vision Library. Versions prior to 4.12.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.
Title GHSL-2025-057 - OpenCV contains a use after free buffer write due to an uninitialized pointer
Weaknesses CWE-457
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-17T17:58:26.493Z

Updated: 2025-08-05T18:37:03.213Z

Reserved: 2025-07-07T14:20:38.391Z

Link: CVE-2025-53644

cve-icon Vulnrichment

Updated: 2025-07-17T20:23:15.553Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-17T18:15:27.913

Modified: 2025-08-05T19:15:41.637

Link: CVE-2025-53644

cve-icon Redhat

Severity : Important

Publid Date: 2025-07-17T17:58:26Z

Links: CVE-2025-53644 - Bugzilla