CVE-2025-22919
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-22919 is a newly identified vulnerability in FFmpeg's git-master branch. It allows an attacker to trigger a Denial of Service (DoS) condition by opening a specially crafted AAC file. The issue stems from a reachable assertion in commit N-113007-g8d24a28d06. The vulnerability does not directly disclose any sensitive data or provide remote code execution, but it can still cause significant disruptions for users handling AAC files. It is essential for FFmpeg users to apply the necessary patches or updates to mitigate this risk and prevent potential DoS attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- FFmpeg