5.6 CVE-2025-47256

Enriched by CISA Exploit
 

Libxmp through 4.6.2 has a stack-based buffer overflow in depack_pha in loaders/prowizard/pha.c via a malformed Pha format tracker module in a .mod file.
https://nvd.nist.gov/vuln/detail/CVE-2025-47256

Categories

CWE-191 : Integer Underflow (Wrap or Wraparound)
This can happen in signed and unsigned cases.

References


 

AFFECTED (from MITRE)


Vendor Product Versions
Libxmp Libxmp
  • ≤ 4.6.2 [affected]
© 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

CPE

cpe start end


REMEDIATION




EXPLOITS


Exploit-db.com

id description date
No known exploits

POC Github

Url
https://github.com/SexyShoelessGodofWar/CVE-2025-47256

Other Nist (github, ...)

Url
No known exploits


CAPEC


Common Attack Pattern Enumerations and Classifications

id description severity
No entry