A vulnerability was found in saitoha libsixel up to 1.10.3. Affected by this issue is the function sixeldebugprint_palette of the file src/encoder.c of the component img2sixel. The manipulation results in stack-based buffer overflow. The attack must be initiated from a local position. The exploit has been made public and could be used. The patch is identified as 316c086e79d66b62c0c4bc66229ee894e4fdb7d1. Applying a patch is advised to resolve this issue.
{
"cwe_ids": [
"CWE-119",
"CWE-121"
],
"cna_assigner": "VulDB",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "1.10.0"
},
{
"last_affected": "1.10.0"
},
{
"introduced": "1.10.1"
},
{
"last_affected": "1.10.1"
},
{
"introduced": "1.10.2"
},
{
"last_affected": "1.10.2"
},
{
"introduced": "1.10.3"
},
{
"last_affected": "1.10.3"
}
]
}
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9300.json"
}{
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:saitoha:libsixel:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.8.7"
}
]
}[
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"324341800310160323184982437435675500935",
"239212271903271994781398894234890973052",
"255605245299660600253827363630067496152",
"76709793144735232411283228931123182352",
"252586162127490786426823653755694609801",
"339985645142845336691561340843632246979",
"237216805159618240505545109782195305875"
]
},
"deprecated": false,
"source": "https://github.com/saitoha/libsixel/commit/316c086e79d66b62c0c4bc66229ee894e4fdb7d1",
"signature_type": "Line",
"target": {
"file": "src/encoder.c"
},
"signature_version": "v1",
"id": "CVE-2025-9300-4602e085"
},
{
"digest": {
"length": 316.0,
"function_hash": "333227096889767899294724403782450659792"
},
"deprecated": false,
"source": "https://github.com/saitoha/libsixel/commit/316c086e79d66b62c0c4bc66229ee894e4fdb7d1",
"signature_type": "Function",
"target": {
"file": "src/encoder.c",
"function": "sixel_debug_print_palette"
},
"signature_version": "v1",
"id": "CVE-2025-9300-be8ec105"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-9300.json"
"2026-07-22T00:05:50Z"