NIXPKGS-2026-0061
GitHub issue
published on
Permalink
CVE-2025-15533
5.3 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Local (L)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): Low (L)
- User Interaction (UI): None (N)
- Scope (S): Unchanged (U)
- Confidentiality (C): Low (L)
- Integrity (I): Low (L)
- Availability (A): Low (L)
- Exploit Code Maturity (E): Proof-of-Concept (P)
- Remediation Level (RL): Official Fix (O)
- Report Confidence (RC): Confirmed (C)
- Modified Attack Vector (MAV): Local (L)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): None (N)
- Modified Confidentiality (MC): Low (L)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): Low (L)
- Modified Availability (MA): Low (L)
by @mweinelt Activity log
- Created suggestion
-
@mweinelt
ignored
5 packages
- raylib-games
- ocamlPackages.raylib
- haskellPackages.h-raylib
- python312Packages.raylib-python-cffi
- python313Packages.raylib-python-cffi
- @mweinelt deleted maintainer @Sigmanificient maintainer.delete
- @mweinelt added maintainer @ehmry maintainer.add
- @mweinelt deleted maintainer @ehmry maintainer.delete
- @mweinelt accepted
- @mweinelt published on GitHub
raysan5 raylib rtext.c GenImageFontAtlas heap-based overflow
A vulnerability was determined in raysan5 raylib up to 909f040. Affected by this vulnerability is the function GenImageFontAtlas of the file src/rtext.c. Executing a manipulation can lead to heap-based buffer overflow. The attack can only be executed locally. The exploit has been publicly disclosed and may be utilized. This patch is called 5a3391fdce046bc5473e52afbd835dd2dc127146. Applying a patch is advised to resolve this issue.
References
-
VDB-341705 | raysan5 raylib rtext.c GenImageFontAtlas heap-based overflow vdb-entrytechnical-description
-
-
Submit #733341 | raysan5 raylib 909f040 Heap-based Buffer Overflow third-party-advisory
-
Submit #733342 | raysan5 raylib 909f040 Heap-based Buffer Overflow (Duplicate) third-party-advisory
-
https://github.com/raysan5/raylib/issues/5433 issue-tracking
-
https://github.com/raysan5/raylib/pull/5450 issue-tracking
Affected products
raylib
- ==909f040
Matching in nixpkgs
Ignored packages (5)
pkgs.raylib-games
Collection of games made with raylib
-
nixos-unstable 2022-10-24
- nixpkgs-unstable 2022-10-24
- nixos-unstable-small 2022-10-24
pkgs.ocamlPackages.raylib
OCaml bindings for Raylib (5.0.0)
pkgs.haskellPackages.h-raylib
Raylib bindings for Haskell
pkgs.python312Packages.raylib-python-cffi
Python CFFI bindings for Raylib
pkgs.python313Packages.raylib-python-cffi
Python CFFI bindings for Raylib
Package maintainers
-
@diniamo diniamo <diniamo53@gmail.com>