CVE-2025-4638
Improper Pointer Arithmetic in pcl
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib.
A flaw was found in the inftrees.c component of the zlib library bundled within the PointCloudLibrary (PCL). This vulnerability allows context-dependent attackers to cause undefined behavior via improper pointer arithmetic.
An update for zlib is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2025-05-13 CVE Reserved
- 2025-05-14 CVE Published
- 2025-05-15 CVE Updated
- 2025-06-15 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-125: Out-of-bounds Read
CAPEC
References (5)
URL | Tag | Source |
---|---|---|
https://github.com/PointCloudLibrary/pcl/blob/master/surface/CMakeLists.txt#L70 | ||
https://github.com/PointCloudLibrary/pcl/commit/502bd2b013ce635f21632d523aa8cf2e04f7b7ac |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/PointCloudLibrary/pcl/pull/6245 | 2025-05-14 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2025-4638 | 2025-05-29 | |
https://bugzilla.redhat.com/show_bug.cgi?id=2366317 | 2025-05-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
- | - | - | - | - |