CVE-2025-4638

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-4638
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-4638.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-4638
Related
Published
2025-05-14T18:15:33Z
Modified
2025-05-17T14:06:35.211618Z
Summary
[none]
Details

A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic.

Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITHSYSTEMZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib.

References

Affected packages

Git / github.com/pointcloudlibrary/pcl

Affected ranges

Type
GIT
Repo
https://github.com/pointcloudlibrary/pcl
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

pcl-1.*

pcl-1.0-ros
pcl-1.10.0
pcl-1.10.1
pcl-1.11.0
pcl-1.11.1
pcl-1.11.1-rc1
pcl-1.11.1-rc2
pcl-1.12.0
pcl-1.12.0-rc1
pcl-1.12.1
pcl-1.13.0
pcl-1.13.0-rc1
pcl-1.8.0
pcl-1.8.0rc1
pcl-1.8.0rc2
pcl-1.9.0
pcl-1.9.1