CVE-2025-59734
Last modified
CVE-2025-59734 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. It is possible to cause an use-after-free write in SANM decoding with a carefully crafted animation using subversion <2. When a STOR chunk is present, a subsequent FOBJ chunk will be saved in ctx->stored_frame. Stored frames can later be referenced by FTCH chunks. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
It is possible to cause an use-after-free write in SANM decoding with a carefully crafted animation using subversion <2. When a STOR chunk is present, a subsequent FOBJ chunk will be saved in ctx->stored_frame. Stored frames can later be referenced by FTCH chunks. For files using subversion < 2, the undecoded frame is stored, and decoded again when the FTCH chunks are parsed. However, in process_frame_obj if the frame has an invalid size, there’s an early return, with a value of 0. This causes the code in decode_frame to still store the raw frame buffer into ctx->stored_frame. Leaving ctx->has_dimensions set to false. A subsequent chunk with type FTCH would call process_ftch and decode that frame obj again, adding to the top/left values and calling process_frame_obj again. Given that we never set ctx->have_dimensions before, this time we set the dimensions, calling init_buffers, which can reallocate the buffer in ctx->stored_frame, freeing the previous one. However, the GetByteContext object gb still holds a reference to the old buffer. Finally, when the code tries to decode the frame, codecs that accept a GetByteContext as a parameter will trigger a use-after-free read when using gb. GetByteContext is only used for reading bytes, so at most one could read invalid data. There are no heap allocations between the free and when the object is accessed. However, upon returning to process_ftch, the code restores the original values for top/left in stored_frame, writing 4 bytes to the freed data at offset 6, potentially corrupting the allocator’s metadata. This issue can be triggered just by probing whether a file has the sanm format. We recommend upgrading to version 8.0 or beyond.
Metrics
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-59734?
How severe is CVE-2025-59734?
How do I fix CVE-2025-59734?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-59729When parsing the header for a DHAV file, there's an integer …5.7
- CVE-2025-5973A vulnerability classified as problematic was found in PHPGu…5.4
- CVE-2025-59730When decoding a frame for a SANM file (ANIM v0 variant), the…5.7
- CVE-2025-59731When decoding an OpenEXR file that uses DWAA or DWAB compres…6.9
- CVE-2025-59732When decoding an OpenEXR file that uses DWAA or DWAB compres…8.7
- CVE-2025-59733When decoding an OpenEXR file that uses DWAA or DWAB compres…8.7
- CVE-2025-59735Operating system command injection vulnerability in AndSoft'…9.8
- CVE-2025-59736Operating system command injection vulnerability in AndSoft'…9.8
- CVE-2025-59737Operating system command injection vulnerability in AndSoft'…9.8
- CVE-2025-59738Operating system command injection vulnerability in AndSoft'…9.8
- CVE-2025-59739Operating system command injection vulnerability in AndSoft'…9.8
- CVE-2025-5974A vulnerability, which was classified as problematic, has be…5.4
Are you affected by CVE-2025-59734?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
