logo

CVE-2025-53367: An exploitable out-of-bounds write in DjVuLibre

ID: b3fd434f-f6f2-51ee-9e2f-934909fa7eea

STIX ID: report--b3fd434f-f6f2-51ee-9e2f-934909fa7eea

Feed Name: GitHub Security Lab

Threat Score
70/100

Date Published: 2025-07-03

Date Updated: 2026-04-27

Author: Kevin Backhouse

...
...

GitHub Security Lab disclosed CVE-2025-53367: an out-of-bounds write in DjVuLibre's MMRDecoder::scanruns that can be triggered by a crafted DjVu document and lead to code execution when opened by Linux document viewers (e.g., Evince/Papers). The report describes the faulty pointer handling between lineruns and prevruns, includes code excerpts, and references a proof-of-concept exploit demonstrating execution on Ubuntu 25.04; a fix was released quickly after reporting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.