CVE-2018-25012: Red Hat Enterprise Linux

Critical severity, CVSS 9.1. EPSS: 2.1% chance of exploitation in the next 30 days.

A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in GetLE24().

Affected products

  • Red Hat Enterprise Linux: version 8.0 only
  • Webmproject Libwebp: before 1.0.1 (fixed in 1.0.1)

Published 2021-05-21. Last modified 2026-06-17.