CVE-2025-63757
published 2025-12-18CVE-2025-63757: Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.33%
25.7th percentile
Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:5.1.8-0+deb12u1 (bookworm) | ffmpeg 7:5.1.8-0+deb12u1 (bookworm) |
| ffmpeg | ffmpeg | — | — |
| ffmpeg | ffmpeg | >= 0 < 7:4.3.9-0+deb11u2 | 7:4.3.9-0+deb11u2 |
| ffmpeg | ffmpeg | >= 0 < 7:5.1.8-0+deb12u1 | 7:5.1.8-0+deb12u1 |
| ffmpeg | ffmpeg | >= 0 < 7:7.1.3-0+deb13u1 | 7:7.1.3-0+deb13u1 |
| ffmpeg | ffmpeg | >= 0 < 7:7.1.3-1 | 7:7.1.3-1 |
| ffmpeg | ffmpeg | >= 0 < 7:7.1.1-1ubuntu4.2 | 7:7.1.1-1ubuntu4.2 |
| ffmpeg | ffmpeg | >= 0 < 7:2.8.17-0ubuntu0.1+esm14 | 7:2.8.17-0ubuntu0.1+esm14 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.11-0ubuntu0.1+esm12 | 7:3.4.11-0ubuntu0.1+esm12 |
| ffmpeg | ffmpeg | >= 0 < 7:4.2.7-0ubuntu0.1+esm12 | 7:4.2.7-0ubuntu0.1+esm12 |
| ffmpeg | ffmpeg | >= 0 < 7:4.4.2-0ubuntu0.22.04.1+esm11 | 7:4.4.2-0ubuntu0.22.04.1+esm11 |
| ffmpeg | ffmpeg | >= 0 < 7:6.1.1-3ubuntu5+esm7 | 7:6.1.1-3ubuntu5+esm7 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv8.7HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ffmpeg vulnerabilities
osv·2026-01-27·CVSS 8.7
CVE-2025-59728 [HIGH] ffmpeg vulnerabilities
ffmpeg vulnerabilities
It was discovered that FFmpeg did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10.
(CVE-2025-59728)
It was discovered that FFmpeg did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2025-59731,
CVE-2025-59732)
It was discovered that FFmpeg did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue
OSV
CVE-2025-63757: Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output
osv·2025-12-18·CVSS 7.5
CVE-2025-63757 [HIGH] CVE-2025-63757: Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output
Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.
GHSA
GHSA-r65g-q984-5j72: Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output
ghsa_unreviewed·2025-12-18
CVE-2025-63757 [HIGH] CWE-190 GHSA-r65g-q984-5j72: Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output
Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2026-01-27·CVSS 7.5
CVE-2025-59728 [HIGH] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: Several security issues were fixed in FFmpeg.
It was discovered that FFmpeg did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10.
(CVE-2025-59728)
It was discovered that FFmpeg did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected
Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 25.10. (CVE-2025-59731,
CVE-2025-59732)
It was discovered that FFmpeg did not correctly handle certain memory
operations. An attacker could possibly use this issue to
Red Hat
ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service
vendor_redhat·2025-12-18·CVSS 7.5
CVE-2025-63757 [HIGH] CWE-190 ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service
ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service
Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.
A flaw was found in FFmpeg, an open-source multimedia framework. This vulnerability is an integer overflow within the yuv2ya16_X_c_template function. A remote attacker could exploit this by providing a specially crafted input, leading to a denial of service (DoS), which means the affected system or application would become unavailable.
Statement: This vulnerability is rated Important for Red Hat products. An integer overflow in FFmpeg's `yuv2ya16_X_c_template` function can be exploited by a remote attacker providing specially crafted input, leading to a denial of service. This impacts components like `ffmpeg`
Debian
CVE-2025-63757: ffmpeg - Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswsca...
vendor_debian·2025·CVSS 7.5
CVE-2025-63757 [HIGH] CVE-2025-63757: ffmpeg - Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswsca...
Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.
Scope: local
bookworm: resolved (fixed in 7:5.1.8-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.9-0+deb11u2)
forky: resolved (fixed in 7:7.1.3-1)
sid: resolved (fixed in 7:7.1.3-1)
trixie: resolved (fixed in 7:7.1.3-0+deb13u1)
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-12343 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-12343 [MEDIUM] CVE-2025-12343 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-12343 :
Ffmpeg vulnerability analysis and mitigation
A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.
Source : NVD
## 5.5
Score
Published February 18, 2026
Severity MEDIUM
CNA Score 3.3
Affected Technologies
Ffmpeg
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA
Wiz
CVE-2025-63757 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-63757 [MEDIUM] CVE-2025-63757 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-63757 :
Ffmpeg vulnerability analysis and mitigation
Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.
Source : NVD
## 7.5
Score
Published December 18, 2025
Severity HIGH
CNA Score 7.5
Affected Technologies
Ffmpeg
Linux openSUSE
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 20.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
libavformat58_76-32bit
libavutil56_70-32bit
Sources
Chainguard No Fix Added at: Dec 31, 2025
Debian 11, 12, 13, 14 Severity HIGH Has Fix Added at: Dec 21, 2025
Echo Severity HIGH Has Fix Added at: Dec 21, 2025
Homebrew Severity HIGH No Fix Added at: Dec 31, 2025
N
Wiz
CVE-2025-69693 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-69693 [HIGH] CVE-2025-69693 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-69693 :
Ffmpeg vulnerability analysis and mitigation
Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid indices 0-63). This results in out-of-bounds array access at lines 1554 (decode_cbp8), 1655 (decode_cbp16), and 1419/1421 (get_c4x4_set), potentially leading to memory disclosure or crash. A previous fix in commit 61cbcaf93f added validation only for intra frames. This vulnerability affects the released versions 8.0 (released 2025-08-22) and 8.0.1 (released 2025-11
Wiz
CVE-2025-10256 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2025-10256 [MEDIUM] CVE-2025-10256 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-10256 :
Ffmpeg vulnerability analysis and mitigation
A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.
Source : NVD
## 5.5
Score
Published February 18, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Ffmpeg
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 0.7
Exploitation Probability (EPSS) N
Bugzilla
CVE-2025-63757 ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service [fedora-42]
bugzilla·2025-12-18·CVSS 7.5
CVE-2025-63757 [HIGH] CVE-2025-63757 ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service [fedora-42]
CVE-2025-63757 ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to c
Bugzilla
CVE-2025-63757 ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service [epel-9]
bugzilla·2025-12-18·CVSS 7.5
CVE-2025-63757 [HIGH] CVE-2025-63757 ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service [epel-9]
CVE-2025-63757 ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service [epel-9]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
Fixed in 8.1: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20698 , not backported to any older releases.
Bugzilla
CVE-2025-63757 ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service [fedora-43]
bugzilla·2025-12-18·CVSS 7.5
CVE-2025-63757 [HIGH] CVE-2025-63757 ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service [fedora-43]
CVE-2025-63757 ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
Fixed in 8.1: https://github.com/FFmpeg/FFmpeg/commit/0c6b7f9483a38657c9be824572b4c0c45d4d9fef
Bugzilla
CVE-2025-63757 qt5-qtwebengine: FFmpeg: Integer overflow vulnerability leads to Denial of Service [fedora-42]
bugzilla·2025-12-18·CVSS 7.5
CVE-2025-63757 [HIGH] CVE-2025-63757 qt5-qtwebengine: FFmpeg: Integer overflow vulnerability leads to Denial of Service [fedora-42]
CVE-2025-63757 qt5-qtwebengine: FFmpeg: Integer overflow vulnerability leads to Denial of Service [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's po
2025-12-18
Published