PatchSiren cyber security CVE debrief
CVE-2016-9085 Fedoraproject CVE debrief
CVE-2016-9085 covers multiple integer overflows in libwebp. The public record ties the issue to libwebp upstream and to affected Fedora packages, with NVD rating the weakness as low severity and limited to availability impact in its CVSS vector. This is primarily a patch-and-rebuild issue for software that ships or embeds libwebp, rather than a high-priority internet-facing emergency.
- Vendor
- Fedoraproject
- Product
- Unknown
- CVSS
- LOW 3.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-03
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-03
- Advisory updated
- 2026-05-13
Who should care
Security teams, Linux distribution maintainers, and application owners that package or embed libwebp, especially environments running affected Fedora 24/25 builds or libwebp versions up to 0.5.2.
Technical summary
NVD classifies the flaw as CWE-190 (integer overflow) in libwebp. The recorded CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L, indicating a locally exploitable issue with low availability impact. The NVD CPE data identifies vulnerable libwebp versions through 0.5.2 and Fedora 24 and 25 packages.
Defensive priority
Low. The issue is publicly known and should be remediated where libwebp is present, but the recorded severity and local-access prerequisites suggest it is not an urgent emergency compared with remotely exploitable or high-impact vulnerabilities.
Recommended defensive actions
- Verify whether your software stack ships libwebp directly or via a bundled dependency.
- Update or rebuild against a patched libwebp version where available; NVD lists vulnerability coverage through libwebp 0.5.2.
- Apply the relevant Fedora package updates for Fedora 24 and 25 if those environments are still in scope.
- Use package inventory and dependency scanning to find applications that consume libwebp so fixes reach downstream builds.
- Review vendor or distribution advisories linked from the CVE record before scheduling maintenance windows.
Evidence notes
The description in the supplied CVE record states 'Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.' NVD metadata identifies CWE-190 and lists affected libwebp versions up to 0.5.2, plus Fedora 24 and 25 CPEs. The record also includes upstream and distribution references, including an oss-security mailing list post dated 2016-10-27 and a libwebp patch reference.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-9085 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-9085
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-9085 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-9085
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://chromium.googlesource.com/webm/libwebp/+/e2affacc35f1df6cc3b1a9fa0ceff5ce2d0cce83
[email protected] - Issue Tracking, Patch, Third Party Advisory
-
Source reference
Unverified legacy reference
URL: https://lists.apache.org/thread.html/rf9fa47ab66495c78bb4120b0754dd9531ca2ff0430f6685ac9b07772%40%3Cdev.mina.apache.org%3E
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LG5Q42J7EJDKQKWTTHCO4YZMOMP74YPQ/
-
Source reference
Unverified legacy reference
URL: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PTR2ZW67TMT7KC24RBENIF25KWUJ7VPD/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.