{"id":"CVE-2025-14958","summary":"floooh sokol sokol_gfx.h _sg_pipeline_common_init heap-based overflow","details":"A security flaw has been discovered in floooh sokol up to 33e2271c431bf21de001e972f72da17a984da932. This vulnerability affects the function _sg_pipeline_common_init in the library sokol_gfx.h. Performing manipulation results in heap-based buffer overflow. The attack needs to be approached locally. The exploit has been released to the public and may be exploited. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The patch is named 33e2271c431bf21de001e972f72da17a984da932. It is suggested to install a patch to address this issue.","modified":"2026-08-12T15:13:40.479543Z","published":"2025-12-19T17:32:08.136Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14958.json","unresolved_ranges":[{"extracted_events":[{"introduced":"33e2271c431bf21de001e972f72da17a984da932"},{"last_affected":"33e2271c431bf21de001e972f72da17a984da932"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14958.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14958"},{"type":"ADVISORY","url":"https://vuldb.com/?id.337594"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.717320"},{"type":"REPORT","url":"https://github.com/floooh/sokol/issues/1406"},{"type":"REPORT","url":"https://github.com/floooh/sokol/issues/1406#issuecomment-3649515551"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.337594"},{"type":"FIX","url":"https://github.com/seyhajin/sokol/commit/33e2271c431bf21de001e972f72da17a984da932"},{"type":"EVIDENCE","url":"https://github.com/oneafter/1212/blob/main/hbf1"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/seyhajin/sokol","events":[{"introduced":"0"},{"fixed":"33e2271c431bf21de001e972f72da17a984da932"}],"database_specific":{"source":"REFERENCES"}}],"versions":["pre-feb2021-api-changes","pre-webgpu","old-pixelformats"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14958.json","vanir_signatures_modified":"2026-08-12T15:13:40Z","vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/seyhajin/sokol/commit/33e2271c431bf21de001e972f72da17a984da932","target":{"file":"sokol_gfx.h"},"deprecated":false,"digest":{"line_hashes":["292622784477154656710410040940503895086","50027860838152742754008816563051884883","211790450921216105222885556098357843697","105462582608778994641139279806659673022"],"threshold":0.9},"id":"CVE-2025-14958-15a9521c"},{"deprecated":false,"digest":{"length":1665,"function_hash":"206976225858040509641056237971519576969"},"id":"CVE-2025-14958-96f8e976","signature_type":"Function","signature_version":"v1","source":"https://github.com/seyhajin/sokol/commit/33e2271c431bf21de001e972f72da17a984da932","target":{"file":"sokol_gfx.h","function":"_sg_pipeline_common_init"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}