Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-71319

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.

A flaw was found in image-size. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by supplying specially crafted JXL, HEIF, or JP2 image files that contain zero-sized boxes. The findBox function, responsible for image validation, enters an infinite loop when processing these malicious files, leading to an application hang. This can disrupt the availability of services relying on the image-size component.

Отчет

This is an Important denial of service vulnerability in the image-size component, which can be triggered remotely by processing specially crafted JXL, HEIF, or JP2 image files containing zero-sized boxes. This flaw can lead to an application hang due to an infinite loop in the findBox function, impacting the availability of services that rely on this image processing library within Red Hat products.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Gatekeeper 3gatekeeper/gatekeeper-rhel9Affected
Red Hat Build of Podman Desktoprh-podman-desktop.gitNot affected
Red Hat Enterprise Linux 7subscription-managerNot affected
Red Hat Enterprise Linux 8grafanaNot affected
Red Hat Enterprise Linux 8grafana-pcpNot affected
Red Hat Enterprise Linux 8subscription-managerWill not fix
Red Hat Fuse 7image-sizeNot affected
Red Hat JBoss Enterprise Application Platform 7image-sizeNot affected
Red Hat JBoss Enterprise Application Platform 8image-sizeNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packimage-sizeNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2487296image-size: image-size: Denial of Service due to infinite loop when processing specially crafted images.

EPSS

Процентиль: 51%
0.00729
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-valued size field in a recognized box-type. Attackers can trigger an infinite loop in the JXL or HEIF image parsers by providing a crafted image containing a box with a size of zero, causing the offset to never advance and permanently hanging the application.

CVSS3: 7.5
github
больше 1 года назад

image-size Denial of Service via Infinite Loop during Image Processing

EPSS

Процентиль: 51%
0.00729
Низкий

7.5 High

CVSS3