{
  "threat_severity" : "Important",
  "public_date" : "2025-07-17T17:58:26Z",
  "bugzilla" : {
    "description" : "opencv: OpenCV use after free",
    "id" : "2381763",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2381763"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
    "status" : "draft"
  },
  "cwe" : "CWE-457",
  "details" : [ "OpenCV is an Open Source Computer Vision Library. Versions 4.10.0 and 4.11.0 have an uninitialized pointer variable on stack that may lead to arbitrary heap buffer write when reading crafted JPEG images. Version 4.12.0 fixes the vulnerability.", "A heap buffer write flaw was found in OpenCV. This vulnerability could result in arbitrary memory overwrites and code execution within the context of a program using OpenCV." ],
  "statement" : "No Red Hat products or offerings are affected by this vulnerability as the vulnerable code is not present in opencv-3.4 that is shipped with Red Hat Enterprise Linux.",
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise Linux 6",
    "fix_state" : "Not affected",
    "package_name" : "opencv",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6"
  }, {
    "product_name" : "Red Hat Enterprise Linux 7",
    "fix_state" : "Not affected",
    "package_name" : "opencv",
    "cpe" : "cpe:/o:redhat:enterprise_linux:7"
  }, {
    "product_name" : "Red Hat Enterprise Linux 8",
    "fix_state" : "Not affected",
    "package_name" : "opencv",
    "cpe" : "cpe:/o:redhat:enterprise_linux:8"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2025-53644\nhttps://nvd.nist.gov/vuln/detail/CVE-2025-53644\nhttps://github.com/opencv/opencv/commit/a39db41390de546d18962ee1278bd6dbb715f466\nhttps://github.com/opencv/opencv/issues/27271\nhttps://github.com/opencv/opencv/releases/tag/4.12.0\nhttps://securitylab.github.com/advisories/GHSL-2025-057_OpenCV/" ],
  "name" : "CVE-2025-53644",
  "mitigation" : {
    "value" : "Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.",
    "lang" : "en:us"
  },
  "csaw" : false
}