Vulnerability Description
Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/GCatt-AS/CVE-2025-47256
- https://github.com/libxmp/libxmp/blob/ec22d1c7b93c8f681f8504a6c61c6f8a52458a10/s
- https://github.com/libxmp/libxmp/issues/847
FAQ
What is CVE-2025-47256?
CVE-2025-47256 is a vulnerability with a CVSS score of 5.6 (MEDIUM). Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.
How severe is CVE-2025-47256?
CVE-2025-47256 has been rated MEDIUM with a CVSS base score of 5.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-47256?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.