---
id: CVE-2025-7345
title: >-
  A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment
  function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c)
summary: >-
  A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment
  function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When
  processing maliciously crafted JPEG images, a heap buffer overflow can occur
  duri…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-120
published: '2025-07-08'
updated: '2026-06-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-7345'
references:
  - url: 'https://access.redhat.com/errata/RHSA-2025:12841'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:12862'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:13315'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14574'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14575'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14576'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14585'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14618'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14646'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14647'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/errata/RHSA-2025:14683'
    label: secalert@redhat.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-7345'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2377063'
    label: secalert@redhat.com
  - url: 'https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/249'
    label: secalert@redhat.com
  - url: 'https://lists.debian.org/debian-lts-announce/2025/10/msg00024.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.01157
epssPercentile: 0.65674
ingestedAt: '2026-06-29T13:24:34.386Z'
---

## Overview

A flaw exists in gdk‑pixbuf within the gdk_pixbuf__jpeg_image_load_increment function (io-jpeg.c) and in glib’s g_base64_encode_step (glib/gbase64.c). When processing maliciously crafted JPEG images, a heap buffer overflow can occur during Base64 encoding, allowing out-of-bounds reads from heap memory, potentially causing application crashes or arbitrary code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
