Description

A flaw was found in libgepub, a library used to read EPUB files. The software mishandles file size calculations when opening specially crafted EPUB files, leading to incorrect memory allocations. This issue causes the application to crash. Known affected usage includes desktop services like Tumbler, which may process malicious files automatically when browsing directories. While no direct remote attack vectors are confirmed, any application using libgepub to parse user-supplied EPUB content could be vulnerable to a denial of service.

INFO

Published Date :

2025-06-17T14:29:42.228Z

Last Modified :

2025-11-06T23:36:57.672Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-6196 vulnerability.

Vendors Products
Gnome
  • Libgepub
Redhat
  • Enterprise Linux

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact