CVE-2025-63757Integer Overflow or Wraparound in Ffmpeg

Severity
7.5HIGHNVD
OSV8.7
EPSS
0.1%
top 75.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 18
Latest updateJan 27

Description

Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/ffmpeg< ffmpeg 7:5.1.8-0+deb12u1 (bookworm)
Debianffmpeg/ffmpeg< 7:4.3.9-0+deb11u2+3
Ubuntuffmpeg/ffmpeg< 7:7.1.1-1ubuntu4.2+5

Patches

🔴Vulnerability Details

3
OSV
ffmpeg vulnerabilities2026-01-27
OSV
CVE-2025-63757: Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output2025-12-18
GHSA
GHSA-r65g-q984-5j72: Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output2025-12-18

📋Vendor Advisories

3
Ubuntu
FFmpeg vulnerabilities2026-01-27
Red Hat
ffmpeg: FFmpeg: Integer overflow vulnerability leads to Denial of Service2025-12-18
Debian
CVE-2025-63757: ffmpeg - Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswsca...2025

🕵️Threat Intelligence

4
Wiz
CVE-2025-12343 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2025-63757 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2025-69693 Impact, Exploitability, and Mitigation Steps | Wiz
Wiz
CVE-2025-10256 Impact, Exploitability, and Mitigation Steps | Wiz