Description
A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:LExploitability: 3.9 | Impact: 1.4Attack Vector: Network
Complexity: Low
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: None
Availability: Low
Affected Packages3 packages
🔴Vulnerability Details
3OSVCVE-2025-7700: A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures↗2025-11-07 ▶ GHSAGHSA-p7g8-g57p-r8qx: A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures↗2025-11-07 ▶ OSVffmpeg vulnerabilities↗2025-10-21 ▶ 📋Vendor Advisories
4UbuntuFFmpeg vulnerability↗2025-11-16 ▶ UbuntuFFmpeg vulnerabilities↗2025-10-21 ▶ Red HatFFmpeg: NULL Pointer Dereference in FFmpeg ALS Decoder (libavcodec/alsdec.c)↗2025-07-15 ▶ DebianCVE-2025-7700: ffmpeg - A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check...↗2025 ▶ 🕵️Threat Intelligence
4WizCVE-2025-12343 Impact, Exploitability, and Mitigation Steps | Wiz↗ ▶ WizCVE-2025-63757 Impact, Exploitability, and Mitigation Steps | Wiz↗ ▶ WizCVE-2025-69693 Impact, Exploitability, and Mitigation Steps | Wiz↗ ▶ WizCVE-2025-10256 Impact, Exploitability, and Mitigation Steps | Wiz↗ ▶