In multiple locations, there is a possible way to achieve code execution due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Is CVE-2025-48595 exploited?
Listed in the CISA KEV catalog on 2026-06-02.
Federal remediation due 2026-06-05.
Past that date by 71 days.
EPSS puts exploitation in the next 30 days at 2%.
Public exploit code: none found in monitored sources.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2025-48595
PlainSec has not published a story about this CVE.