CVE-2018-25011
Description
A heap-based buffer overflow was found in libwebp in versions before 1.0.1 in PutLE16().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A heap-based buffer overflow in libwebp's PutLE16() function before version 1.0.1 could lead to memory corruption.
Vulnerability
A heap-based buffer overflow exists in the PutLE16() function in libwebp versions before 1.0.1, as identified in [1]. The issue occurs when writing 16-bit values into a buffer without sufficient bounds checking, potentially allowing an attacker to corrupt heap memory. Affected versions include all libwebp releases prior to 1.0.1, which was released on November 2, 2018 [3].
Exploitation
An attacker needs to craft a maliciously formed input file (e.g., WebP image) that triggers the vulnerable code path in PutLE16(). The vulnerability was discovered through fuzzing (oss-fuzz issue #9119) [1], indicating that it can be triggered by malformed data processed by libwebp. No authentication or special privileges are required; the attack vector is remote, exploiting the library via a crafted image.
Impact
Successful exploitation can lead to heap corruption, potentially resulting in denial of service (crash) or arbitrary code execution (RCE) in the context of the process using libwebp. The vulnerability could allow an attacker to overwrite adjacent heap memory, leading to control flow hijacking. The scope of compromise depends on the application using libwebp, but this is considered a high-severity issue due to the possibility of memory corruption.
Mitigation
Upgrade to libwebp version 1.0.1 or later, which includes the fix [1][3]. The upstream patch is available in the repository [2]. Red Hat Enterprise Linux 7 users received the fix via RHSA-2021:2260 [1]. If upgrading is not immediately possible, application-level input validation or sandboxing may reduce risk. No workaround is provided for the vulnerable function itself.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
35- libwebp/libwebpdescription
- Range: <1.0.1
- osv-coords33 versionspkg:rpm/opensuse/libwebp&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/libwebp&distro=HPE%20Helion%20OpenStack%208pkg:rpm/suse/libwebp&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP2pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP3pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCLpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCLpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-LTSSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP2pkg:rpm/suse/libwebp&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2015%20SP3pkg:rpm/suse/libwebp&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/libwebp&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/libwebp&distro=SUSE%20Manager%20Server%204.0pkg:rpm/suse/libwebp&distro=SUSE%20OpenStack%20Cloud%207pkg:rpm/suse/libwebp&distro=SUSE%20OpenStack%20Cloud%208pkg:rpm/suse/libwebp&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/libwebp&distro=SUSE%20OpenStack%20Cloud%20Crowbar%208pkg:rpm/suse/libwebp&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
< 0.5.0-3.5.1+ 32 more
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.5.0-3.5.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
- (no CPE)range: < 0.4.3-4.7.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- bugs.chromium.org/p/oss-fuzz/issues/detailmitrex_refsource_MISC
- bugzilla.redhat.com/show_bug.cgimitrex_refsource_MISC
- chromium.googlesource.com/webm/libwebp/+/v1.0.1mitrex_refsource_MISC
- chromium.googlesource.com/webm/libwebp/+log/be738c6d396fa5a272c1b209be4379a7532debfe..29fb8562c60b5a919a75d904ff7366af423f8ab9mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.