CVE-2025-47256

Name
CVE-2025-47256
Description
Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/GCatt-AS/CVE-2025-47256
cve@mitre.org https://github.com/libxmp/libxmp/blob/ec22d1c7b93c8f681f8504a6c61c6f8a52458a10/src/loaders/prowizard/pha.c#L35
cve@mitre.org https://github.com/libxmp/libxmp/issues/847

Match rules

CPE URI Source package Min version Max version
libxmp >= 0 <= 4.6.2

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
libxmp edge-community 4.6.0-r1 Dominika Liberda <ja@sdomi.pl> possibly vulnerable
libxmp 3.22-community 4.6.0-r1 Dominika Liberda <ja@sdomi.pl> possibly vulnerable