CVE-2025-15534 is an integer overflow vulnerability in the LoadFontData function of raysan5 raylib (up to commit 909f040), specifically within the src/rtext.c file. This flaw carries a CVSSv3.1 score of 7.8 (High), indicating a significant risk due to its local attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While a public exploit is available, there is currently no evidence of active exploitation, Metasploit/Nuclei modules, or significant community discussion or media coverage. Organizations are advised to apply the provided patch (5a3391fdce046bc5473e52afbd835dd2dc127146) to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026-01-01CPE matchmatch criteria | cpe:2.3:a:raylib:raylib:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.