cbcvebase.
CVE-2025-59731
published 2025-10-06

CVE-2025-59731: When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is not checked when using it to calculate…

PriorityP426medium6.9CVSS 4.0
AVAACHATNPRLUIPVCHVIHVANSCHSIHSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.16%
5.7th percentile
When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is not checked when using it to calculate the output data. We read rle_raw_size from the input file at [0], we decompress and decode into the buffer td->rle_raw_data of size rle_raw_size at [1], and then at [2] we will access entries in this buffer up to (td->xsize - 1) * (td->ysize - 1) + rle_raw_size / 2, which may exceed rle_raw_size. We recommend upgrading to version 8.0 or beyond.

Affected

12 ranges
VendorProductVersion rangeFixed in
debianffmpeg< ffmpeg 7:5.1.7-0+deb12u1 (bookworm)ffmpeg 7:5.1.7-0+deb12u1 (bookworm)
ffmpegffmpeg>= 0 < 7:5.1.7-0+deb12u17:5.1.7-0+deb12u1
ffmpegffmpeg>= 0 < 7:7.1.2-0+deb13u17:7.1.2-0+deb13u1
ffmpegffmpeg>= 0 < 7:7.1.2-17:7.1.2-1
ffmpegffmpeg>= 0 < 7:7.1.1-1ubuntu4.27:7.1.1-1ubuntu4.2
ffmpegffmpeg>= 0 < 7:2.8.17-0ubuntu0.1+esm147:2.8.17-0ubuntu0.1+esm14
ffmpegffmpeg>= 0 < 7:3.4.11-0ubuntu0.1+esm127:3.4.11-0ubuntu0.1+esm12
ffmpegffmpeg>= 0 < 7:4.2.7-0ubuntu0.1+esm127:4.2.7-0ubuntu0.1+esm12
ffmpegffmpeg>= 0 < 7:4.4.2-0ubuntu0.22.04.1+esm117:4.4.2-0ubuntu0.22.04.1+esm11
ffmpegffmpeg>= 0 < 7:6.1.1-3ubuntu5+esm77:6.1.1-3ubuntu5+esm7
ffmpegffmpeg>= 7.1.1 < 8.08.0
ffmpegffmpeg>= 9a32b863074ed4140141e0d3613905c6f1fe61c5 < 8.08.0

CVSS provenance

nvdv4.06.9MEDIUMCVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv8.7HIGH
vendor_ubuntu7.5HIGH
vendor_debian6.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.