{"id":"CVE-2025-4638","summary":"Improper Pointer Arithmetic in pcl","details":"A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic.\n\nSince version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib.","modified":"2026-08-12T15:16:32.116084Z","published":"2025-05-14T17:59:58.180Z","database_specific":{"cna_assigner":"GovTech CSG","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4638.json"},"references":[{"type":"WEB","url":"https://github.com/PointCloudLibrary/pcl/blob/master/surface/CMakeLists.txt#L70"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/4xxx/CVE-2025-4638.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-4638"},{"type":"FIX","url":"https://github.com/PointCloudLibrary/pcl/commit/502bd2b013ce635f21632d523aa8cf2e04f7b7ac"},{"type":"FIX","url":"https://github.com/PointCloudLibrary/pcl/pull/6245"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pointcloudlibrary/pcl","events":[{"introduced":"0"},{"fixed":"f62c018b4fc7df3dc2c096918a8462a190f28bb8"},{"fixed":"502bd2b013ce635f21632d523aa8cf2e04f7b7ac"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.14.0"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:pointclouds:point_cloud_library:*:*:*:*:*:*:*:*"}}],"versions":["pcl-1.14.0-rc1","pcl-1.13.1","pcl-1.13.1-rc1","pcl-1.13.0-rc1","pcl-1.13.0","pcl-1.12.1","pcl-1.12.0-rc1","pcl-1.12.0","pcl-1.11.1","pcl-1.11.1-rc2","pcl-1.11.1-rc1","pcl-1.11.0","pcl-1.10.1","pcl-1.10.0","pcl-1.9.1","pcl-1.9.0","pcl-1.8.0","pcl-1.8.0rc2","pcl-1.8.0rc1","pcl-1.0-ros"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-4638.json","vanir_signatures_modified":"2026-08-12T15:16:32Z","vanir_signatures":[{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["142507249250011048393637035603308527531","183792250313666141464654538174142285961","322051085261934477892702746723805144375","9645395726226507733371715164106126177"]},"id":"CVE-2025-4638-896ffc9a","signature_type":"Line","signature_version":"v1","source":"https://github.com/pointcloudlibrary/pcl/commit/502bd2b013ce635f21632d523aa8cf2e04f7b7ac","target":{"file":"surface/include/pcl/surface/3rdparty/opennurbs/opennurbs_zlib.h"}},{"signature_type":"Line","signature_version":"v1","source":"https://github.com/pointcloudlibrary/pcl/commit/502bd2b013ce635f21632d523aa8cf2e04f7b7ac","target":{"file":"surface/src/3rdparty/opennurbs/opennurbs_zlib.cpp"},"deprecated":false,"digest":{"line_hashes":["136782776953135412937467136059416465158","110458794268363846693089669238631539255","263354597587748154763020415750074237993","223821636524468299286273832382372485888","279542666357318067735418905776482282396","227309763869449294412943433381806967990","300024253196399538696656521684273235706","20525459871724096279244981191323258620","307797107683726936971583923656594890370"],"threshold":0.9},"id":"CVE-2025-4638-ee2f2f5d"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:L/SA:H/AU:Y/R:U/V:D/RE:M/U:Amber"}]}