CVE-2025-29070
ADVISORY - nistSummary
A heap buffer overflow vulnerability has been identified in thesmooth2() in cmsgamma.c in lcms2-2.16 which allows a remote attacker to cause a denial of service. NOTE: the Supplier disputes this because "this is not exploitable as this function is never called on normal color management, is there only as a helper for low-level programming and investigation."
EPSS Score: 0.00907 (0.565)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Heap-based Buffer Overflow
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in