The vulnerability report for CVE-2025-29480 has been disputed by the GDAL maintainers, since it could not be reproduced.
https://github.com/OSGeo/gdal/issues/12188
The report that got the cve: https://github.com/lmarch2/poc/blob/main/gdal/gdal.md
It does seem vague, and there was no follow-up.
https://security-tracker.debian.org/tracker/CVE-2025-29480
We should definitely track this and see if there is an update.