CVE-2025-25468

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Feb 18, 2025
Updated: Feb 19, 2025
CWE ID 200

Summary

CVE-2025-25468 is a newly disclosed memory leak vulnerability in the FFmpeg library, specifically in the libavutil/mem.c component of the git-master version before the commit d5873b. This issue can lead to memory exhaustion and potential denial-of-service attacks. An attacker could manipulate a specially crafted media file to exploit this vulnerability, causing the FFmpeg parse process to leak memory until it becomes unstable and eventually crashes. This vulnerability poses a risk to systems handling media files using the affected FFmpeg version. It is recommended that users upgrade to the latest, patched version of FFmpeg to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share