Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-71330

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to trigger an infinite loop in the ICNS parser, as the offset is never incremented when the entry length field is 0, causing the while loop condition to remain true indefinitely.

A flaw was found in image-size. A remote attacker can exploit this vulnerability by providing a specially crafted ICNS image buffer. This malicious buffer, containing valid magic bytes and a zero-valued entry length, causes an infinite loop in the ICNS parser. This can permanently block the Node.js event loop, leading to a denial of service (DoS) for the affected system.

Отчет

A flaw was found in the image-size npm package. A crafted ICNS image buffer with a zero-valued entry length field can trigger an infinite loop in the ICNS parser, permanently blocking the Node.js event loop and causing a denial of service.

Меры по смягчению последствий

Upgrade to a version of image-size that validates ICNS entry length fields. As a workaround, validate image inputs before passing them to image-size, rejecting ICNS files with zero-length entries.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Gatekeeper 3gatekeeper/gatekeeper-rhel9Fix deferred
Red Hat Build of Podman Desktoprh-podman-desktop.gitFix deferred
Red Hat Discovery 2discovery/discovery-ui-rhel9Fix deferred
Red Hat Enterprise Linux 8grafanaFix deferred
Red Hat Enterprise Linux 8grafana-pcpFix deferred
Red Hat Fuse 7image-sizeFix deferred
Red Hat JBoss Enterprise Application Platform 7image-sizeFix deferred
Red Hat JBoss Enterprise Application Platform 8image-sizeFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packimage-sizeFix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2487553image-size: image-size: Denial of Service via crafted ICNS image buffer

EPSS

Процентиль: 36%
0.0043
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
2 месяца назад

image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attackers can craft an ICNS buffer containing valid magic bytes and a zero-valued entry length field to trigger an infinite loop in the ICNS parser, as the offset is never incremented when the entry length field is 0, causing the while loop condition to remain true indefinitely.

CVSS3: 7.5
github
2 месяца назад

image-size: ICNS parser allows denial of service through an infinite loop

EPSS

Процентиль: 36%
0.0043
Низкий

6.5 Medium

CVSS3