PatchSiren cyber security CVE debrief
CVE-2025-3408 Nothings CVE debrief
A critical integer overflow vulnerability exists in the stb_dupreplace function of Nothings stb image library, affecting versions up to commit f056911. The vulnerability can be triggered remotely through manipulation of the affected function, potentially leading to memory corruption or other undefined behavior. The stb library uses continuous delivery with rolling releases, meaning no traditional version numbers are available for affected or patched releases. The vendor was contacted prior to disclosure but did not respond. Organizations using stb image.h should monitor the official repository for security updates and consider implementing input validation as a defensive measure.
- Vendor
- Nothings
- Product
- stb
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-08
- Original CVE updated
- 2026-05-19
- Advisory published
- 2025-04-08
- Advisory updated
- 2026-05-19
Who should care
Organizations using stb image.h for image processing, particularly those handling untrusted image data from remote sources. Developers maintaining applications with stb dependencies should prioritize monitoring given the vendor's non-response to disclosure.
Technical summary
The stb_dupreplace function in Nothings stb image library contains an integer overflow vulnerability that can be exploited remotely. The library's continuous delivery model with rolling releases complicates patch tracking, as security fixes are committed without versioned releases. The vulnerability is classified under CWE-190 (Integer Overflow or Wraparound) and CWE-189 (Numeric Errors).
Defensive priority
high
Recommended defensive actions
- Monitor the Nothings stb GitHub repository for security commits addressing the stb_dupreplace function
- Implement strict input validation on all image data processed by stb image.h functions
- Consider using memory-safe alternatives or sandboxing for untrusted image processing
- Review and update dependency management to track commit-level changes given the rolling release model
- Conduct code review of stb_dupreplace usage in your applications to identify potential exposure
Evidence notes
Vulnerability identified in stb_dupreplace function leading to integer overflow. CVSS 4.0 vector indicates network attack vector with low attack complexity, no privileges required, but user interaction needed. CPE indicates affected versions up to 2.13. CWE-189 (Numeric Errors) and CWE-190 (Integer Overflow or Wraparound) classified.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-3408 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-3408
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-3408 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-3408
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.