Sploitus

CVE-2025-4638

No indexed exploits for CVE-2025-4638 yet

A vulnerability exists in the inftrees.c component of the zlib library, which is bundled within the PointCloudLibrary (PCL). This issue may allow context-dependent attackers to cause undefined behavior by exploiting improper pointer arithmetic. Since version 1.14.0, PCL by default uses a zlib installation from the system, unless the user sets WITH_SYSTEM_ZLIB=FALSE. So this potential vulnerability is only relevant if the PCL version is older than 1.14.0 or the user specifically requests to not use the system zlib.

Affected products
Pointcloudlibrary, Zlib
Pointclouds Point Cloud Library
< 1.14.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
0.5% (38th percentile)
Weakness
CWE-119
NVD status
Analyzed
Published
2025-05-14
CVE-2025-4638 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-4638 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-4638 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.