CVE-2025-15533 is a high-severity heap-based buffer overflow vulnerability affecting the GenImageFontAtlas function in raysan5 raylib versions up to 909f040. This local vulnerability, with a CVSS score of 7.8, allows an attacker to achieve high confidentiality, integrity, and availability impacts through manipulation. While a public exploit has been disclosed, there is no evidence of active exploitation, and it has received minimal community discussion or media coverage. A patch (5a3391fdce046bc5473e52afbd835dd2dc127146) is available to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026-01-01CPE matchmatch criteria | cpe:2.3:a:raylib:raylib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.