CVE-2025-22919

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 18, 2025
Updated: Feb 19, 2025
CWE ID 617

Summary

CVE-2025-22919 is a newly identified vulnerability in FFmpeg's git-master branch. It allows an attacker to trigger a Denial of Service (DoS) condition by opening a specially crafted AAC file. The issue stems from a reachable assertion in commit N-113007-g8d24a28d06. The vulnerability does not directly disclose any sensitive data or provide remote code execution, but it can still cause significant disruptions for users handling AAC files. It is essential for FFmpeg users to apply the necessary patches or updates to mitigate this risk and prevent potential DoS attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share