CVE-2025-48175 | aomedia libavif up to 1.2.x reformat.c avifImageRGBToYUV rgbRowBytes/yRowBytes/uRowBytes/vRowBytes integer overflow (GHSA-762c-2538-h844 / EUVD-2025-15403)
A vulnerability was found in aomedia libavif up to 1.2.x. It has been declared as problematic. This vulnerability affects the function avifImageRGBToYUV of the file reformat.c. The manipulation of the argument rgbRowBytes/yRowBytes/uRowBytes/vRowBytes leads to integer overflow.
This vulnerability was named CVE-2025-48175. Attacking locally is a requirement. There is no exploit available.
It is recommended to upgrade the affected component.