FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpeg | Jul 27, 2026 | Jul 27, 2026 |
| Ffmpeg | — | Upgrade to FFmpeg version 7.1 | Jun 5, 2025 | Nov 29, 2024 |
| Suse | — | Upgrade libpostproc58Upgrade libavfilter10Upgrade libavformat61Upgrade libavdevice61Upgrade libswresample5Upgrade libavutil59Upgrade libavcodec61Upgrade libswscale8Upgrade ffmpeg-7 | Dec 5, 2025 | May 31, 2025 |
| Ubuntu | — | Upgrade ffmpeg (Ubuntu Pro)Upgrade libavcodec-dev (Ubuntu Pro) | Jun 26, 2025 | Nov 29, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub