vulnerability
Ubuntu: USN-7538-1 (CVE-2025-25473): FFmpeg vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 5 | (AV:N/AC:L/Au:N/C:N/I:P/A:N) | Feb 18, 2025 | May 22, 2025 | Apr 16, 2026 |
Severity
5
CVSS
(AV:N/AC:L/Au:N/C:N/I:P/A:N)
Published
Feb 18, 2025
Added
May 22, 2025
Modified
Apr 16, 2026
Description
FFmpeg git master before commit c08d30 was discovered to contain a memory leak in the avformat_free_context function in libavutil/mem.c.
Solutions
ubuntu-pro-upgrade-ffmpegubuntu-pro-upgrade-libav-toolsubuntu-pro-upgrade-libavcodec-extra57ubuntu-pro-upgrade-libavcodec-extra58ubuntu-pro-upgrade-libavcodec-extra60ubuntu-pro-upgrade-libavcodec-ffmpeg-extra56ubuntu-pro-upgrade-libavcodec-ffmpeg56ubuntu-pro-upgrade-libavcodec57ubuntu-pro-upgrade-libavcodec58ubuntu-pro-upgrade-libavcodec60ubuntu-pro-upgrade-libavdevice-ffmpeg56ubuntu-pro-upgrade-libavdevice57ubuntu-pro-upgrade-libavdevice58ubuntu-pro-upgrade-libavdevice60ubuntu-pro-upgrade-libavfilter-extra6ubuntu-pro-upgrade-libavfilter-extra7ubuntu-pro-upgrade-libavfilter-extra9ubuntu-pro-upgrade-libavfilter-ffmpeg5ubuntu-pro-upgrade-libavfilter6ubuntu-pro-upgrade-libavfilter7ubuntu-pro-upgrade-libavfilter9ubuntu-pro-upgrade-libavformat-extra58ubuntu-pro-upgrade-libavformat-extra60ubuntu-pro-upgrade-libavformat-ffmpeg56ubuntu-pro-upgrade-libavformat57ubuntu-pro-upgrade-libavformat58ubuntu-pro-upgrade-libavformat60ubuntu-pro-upgrade-libavresample-ffmpeg2ubuntu-pro-upgrade-libavresample3ubuntu-pro-upgrade-libavresample4ubuntu-pro-upgrade-libavutil-ffmpeg54ubuntu-pro-upgrade-libavutil55ubuntu-pro-upgrade-libavutil56ubuntu-pro-upgrade-libavutil58ubuntu-pro-upgrade-libpostproc-ffmpeg53ubuntu-pro-upgrade-libpostproc54ubuntu-pro-upgrade-libpostproc55ubuntu-pro-upgrade-libpostproc57ubuntu-pro-upgrade-libswresample-ffmpeg1ubuntu-pro-upgrade-libswresample2ubuntu-pro-upgrade-libswresample3ubuntu-pro-upgrade-libswresample4ubuntu-pro-upgrade-libswscale-ffmpeg3ubuntu-pro-upgrade-libswscale4ubuntu-pro-upgrade-libswscale5ubuntu-pro-upgrade-libswscale7ubuntu-upgrade-ffmpegubuntu-upgrade-libavcodec-extra61ubuntu-upgrade-libavcodec61ubuntu-upgrade-libavdevice61ubuntu-upgrade-libavfilter-extra10ubuntu-upgrade-libavfilter10ubuntu-upgrade-libavformat-extra61ubuntu-upgrade-libavformat61ubuntu-upgrade-libavutil59ubuntu-upgrade-libpostproc58ubuntu-upgrade-libswresample5ubuntu-upgrade-libswscale8
References
- CVE-2025-25473
- https://attackerkb.com/topics/CVE-2025-25473
- CWE-476
- EUVD-EUVD-2025-4559
- UBUNTU-USN-7538-1
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-4559
- https://git.ffmpeg.org/gitweb/ffmpeg.git/blobdiff/4f3c9f2f03378a08692a26532bc3146414717f8c..c08d300481b8ebb846cd43a473988fdbc6793d1b:/libavformat/avformat.c
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/c08d300481b8ebb846cd43a473988fdbc6793d1b
- https://trac.ffmpeg.org/ticket/11419
- https://ubuntu.com/security/notices/USN-7538-1
- https://www.cve.org/CVERecord?id=CVE-2025-25473
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.