A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ffmpeg | Dec 5, 2025 | Feb 18, 2025 |
| Ffmpeg | — | Upgrade to FFmpeg version 8.0 | Aug 25, 2025 | Feb 18, 2025 |
| Suse | — | Upgrade libpostproc58Upgrade libavcodec61Upgrade libavformat61Upgrade ffmpeg-7Upgrade libavfilter10Upgrade libavdevice61Upgrade libswscale8Upgrade libavutil59Upgrade libswresample5 | Dec 5, 2025 | Feb 26, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub