CVE-2025-62813

Public on 2025-10-23
Modified on 2025-10-24
Description
LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.1
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Firefox Extra firefox 2025-11-10 ALAS2FIREFOX-2025-045 Fixed
Amazon Linux 2023 firefox 2025-11-10 ALAS2023-2025-1284 Fixed
Amazon Linux 2 - Core gjs Not Affected
Amazon Linux 2023 gjs Pending Fix
Amazon Linux 2 - Core lz4 2025-11-10 ALAS2-2025-3062 Fixed
Amazon Linux 2023 lz4 2025-11-10 ALAS2023-2025-1266 Fixed
Amazon Linux 2 - Core polkit Not Affected
Amazon Linux 2023 polkit Not Affected
Amazon Linux 2 - Core thunderbird 2025-11-10 ALAS2-2025-3064 Fixed

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H