CVE-2018-25014: Red Hat Enterprise Linux
Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.
A use of uninitialized value was found in libwebp in versions before 1.0.1 in ReadSymbol().
Affected products
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
- Webmproject Libwebp: before 1.0.1 (fixed in 1.0.1)
Published 2021-05-21. Last modified 2026-06-17.