CVE-2025-12343
published 2026-02-18CVE-2025-12343: A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function…
PriorityP424medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.15%
4.6th percentile
A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:7.1.2-1 (forky) | ffmpeg 7:7.1.2-1 (forky) |
| ffmpeg | ffmpeg | >= 0 < 7:7.1.2-0+deb13u1 | 7:7.1.2-0+deb13u1 |
| ffmpeg | ffmpeg | >= 0 < 7:7.1.2-1 | 7:7.1.2-1 |
| ffmpeg | ffmpeg | >= 6.1 < 8.1 | 8.1 |
| ubuntu | ffmpeg | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2026-06-24·CVSS 5.5
CVE-2026-40962 [MEDIUM] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: Several security issues were fixed in FFmpeg.
Jiasheng Jiang discovered that FFmpeg incorrectly handled memory in
certain error-handling paths of its TensorFlow DNN backend. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 24.04 LTS. (CVE-2025-12343)
Quang Luong discovered that FFmpeg incorrectly handled certain subsample
data. An attacker could possibly use this issue to cause a denial of
service or possibly execute arbitrary code. (CVE-2026-40962)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
FFmpeg: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend
vendor_redhat·2025-10-27·CVSS 3.3
CVE-2025-12343 [LOW] CWE-415 FFmpeg: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend
FFmpeg: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend
A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.
A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times
Debian
CVE-2025-12343: ffmpeg - A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backe...
vendor_debian·2025·CVSS 3.3
CVE-2025-12343 [LOW] CVE-2025-12343: ffmpeg - A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backe...
A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 7:7.1.2-1)
sid: resolved (fixed in 7:7.1.2-1)
trixie: resolved (fixed in 7:7.1.2-0+deb13u1)
OSV
CVE-2025-12343: A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf
osv·2026-02-18·CVSS 5.5
CVE-2025-12343 [MEDIUM] CVE-2025-12343: A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf
A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.
GHSA
GHSA-2g52-f4rf-8vm9: A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf
ghsa_unreviewed·2026-02-18
CVE-2025-12343 [LOW] CWE-415 GHSA-2g52-f4rf-8vm9: A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf
A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-12343 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-12343 [MEDIUM] CVE-2025-12343 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-12343 :
Ffmpeg vulnerability analysis and mitigation
A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.
Source : NVD
## 5.5
Score
Published February 18, 2026
Severity MEDIUM
CNA Score 3.3
Affected Technologies
Ffmpeg
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA
Wiz
CVE-2025-63757 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-63757 [MEDIUM] CVE-2025-63757 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-63757 :
Ffmpeg vulnerability analysis and mitigation
Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.
Source : NVD
## 7.5
Score
Published December 18, 2025
Severity HIGH
CNA Score 7.5
Affected Technologies
Ffmpeg
Linux openSUSE
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
libavformat58_76-32bit
libavutil56_70-32bit
Sources
Chainguard No Fix Added at: Dec 31, 2025
Debian 11, 12, 13, 14 Severity HIGH Has Fix Added at: Dec 21, 2025
Echo Severity HIGH Has Fix Added at: Dec 21, 2025
Homebrew Severity HIGH No Fix Added at: Dec 31, 2025
N
Wiz
CVE-2025-69693 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-69693 [HIGH] CVE-2025-69693 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69693 :
Ffmpeg vulnerability analysis and mitigation
Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid indices 0-63). This results in out-of-bounds array access at lines 1554 (decode_cbp8), 1655 (decode_cbp16), and 1419/1421 (get_c4x4_set), potentially leading to memory disclosure or crash. A previous fix in commit 61cbcaf93f added validation only for intra frames. This vulnerability affects the released versions 8.0 (released 2025-08-22) and 8.0.1 (released 2025-11
Wiz
CVE-2025-10256 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-10256 [MEDIUM] CVE-2025-10256 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-10256 :
Ffmpeg vulnerability analysis and mitigation
A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.
Source : NVD
## 5.5
Score
Published February 18, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Ffmpeg
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N
Bugzilla
CVE-2025-12343 qt5-qtwebengine: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend [fedora-42]
bugzilla·2025-10-27·CVSS 5.5
CVE-2025-12343 [MEDIUM] CVE-2025-12343 qt5-qtwebengine: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend [fedora-42]
CVE-2025-12343 qt5-qtwebengine: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to
Bugzilla
CVE-2025-12343 ffmpeg: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend [epel-10]
bugzilla·2025-10-27·CVSS 5.5
CVE-2025-12343 [MEDIUM] CVE-2025-12343 ffmpeg: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend [epel-10]
CVE-2025-12343 ffmpeg: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend [epel-10]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
Fixed in 7.1.2: https://github.com/FFmpeg/FFmpeg/commit/729dd9b2865bedd6a8160ef574db0d391c491bee .
Bugzilla
CVE-2025-12343 ffmpeg: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend [epel-9]
bugzilla·2025-10-27·CVSS 5.5
CVE-2025-12343 [MEDIUM] CVE-2025-12343 ffmpeg: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend [epel-9]
CVE-2025-12343 ffmpeg: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend [epel-9]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
Fix https://github.com/FFmpeg/FFmpeg/commit/729dd9b2865bedd6a8160ef574db0d391c491bee not backported to 5.1.
Bugzilla
CVE-2025-12343 ffmpeg: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend [fedora-42]
bugzilla·2025-10-27·CVSS 5.5
CVE-2025-12343 [MEDIUM] CVE-2025-12343 ffmpeg: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend [fedora-42]
CVE-2025-12343 ffmpeg: Double-Free Vulnerability in FFmpeg TensorFlow DNN Backend [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close al
2026-02-18
Published