CVE-2025-22920
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Feb 18, 2025
Updated: Feb 19, 2025
CWE ID 122
Summary
CVE-2025-22920 is a heap buffer overflow vulnerability affecting FFmpeg before commit 4bf784c. Maliciously crafted media files can be used to trigger this issue during the processing of tile grid group streams in avformat. The memory corruption resulting from this vulnerability can cause a Denial of Service (DoS) incident. Attackers can exploit this vulnerability to cause FFmpeg to crash or consume excessive system resources. This issue poses a significant risk to systems utilizing FFmpeg and should be addressed promptly by applying the necessary patches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share