CVE-2025-48175: Aomedia Libavif

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

In libavif before 1.3.0, avifImageRGBToYUV in reformat.c has integer overflows in multiplications involving rgbRowBytes, yRowBytes, uRowBytes, and vRowBytes.

Affected products

  • Aomedia Libavif: before 1.3.0 (fixed in 1.3.0)

Published 2025-05-16. Last modified 2026-06-17.