CVE-2025-9951
published 2025-09-09CVE-2025-9951: A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the…
PriorityP343high7.2CVSS 4.0
AVNACHATNPRLUINVCNVIHVAHSCNSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.37%
29.9th percentile
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | ffmpeg | < ffmpeg 7:5.1.7-0+deb12u1 (bookworm) | ffmpeg 7:5.1.7-0+deb12u1 (bookworm) |
| ffmpeg | ffmpeg | < 8.0 | 8.0 |
| ffmpeg | ffmpeg | >= 0 < 7:4.3.9-0+deb11u2 | 7:4.3.9-0+deb11u2 |
| ffmpeg | ffmpeg | >= 0 < 7:5.1.7-0+deb12u1 | 7:5.1.7-0+deb12u1 |
| ffmpeg | ffmpeg | >= 0 < 7:7.1.2-0+deb13u1 | 7:7.1.2-0+deb13u1 |
| ffmpeg | ffmpeg | >= 0 < 7:7.1.2-1 | 7:7.1.2-1 |
| ffmpeg | ffmpeg | >= 0 < 7:3.4.11-0ubuntu0.1+esm11 | 7:3.4.11-0ubuntu0.1+esm11 |
| ffmpeg | ffmpeg | >= 0 < 7:4.2.7-0ubuntu0.1+esm11 | 7:4.2.7-0ubuntu0.1+esm11 |
| ffmpeg | ffmpeg | >= 0 < 7:4.4.2-0ubuntu0.22.04.1+esm10 | 7:4.4.2-0ubuntu0.22.04.1+esm10 |
| ffmpeg | ffmpeg | >= 0 < 7:6.1.1-3ubuntu5+esm6 | 7:6.1.1-3ubuntu5+esm6 |
CVSS provenance
nvdv4.07.2HIGHCVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv7.5HIGH
vendor_redhat9.8CRITICAL
vendor_ubuntu7.5HIGH
vendor_debian7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
ffmpeg vulnerabilities
osv·2025-10-21·CVSS 7.5
CVE-2023-6603 [HIGH] ffmpeg vulnerabilities
ffmpeg vulnerabilities
It was discovered that FFmpeg incorrectly handled the return values of
functions in its Firequalizer filter and in the HTTP Live Streaming (HLS)
implementation, leading to a NULL pointer dereference. If a user was
tricked into loading a crafted media file, a remote attacker could
possibly use this issue to make FFmpeg crash, resulting in a denial
of service. (CVE-2023-6603, CVE-2025-10256)
It was discovered that FFmpeg did not enforce an input format before
triggering the HTTP demuxer. A remote attacker could possibly use this
issue to perform a Server-Side Request Forgery (SSRF) attack.
(CVE-2025-6605)
It was discovered that FFmpeg incorrectly handled memory allocation in the
ALS audio decoder. If a user was tricked into loading a crafted media file,
a remote att
OSV
CVE-2025-9951: A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of servic
osv·2025-09-09·CVSS 7.2
CVE-2025-9951 [HIGH] CVE-2025-9951: A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of servic
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
Red Hat
vLLM: vLLM: Remote code execution via invalid image processing in the multimodal endpoint.
vendor_redhat·2026-02-02·CVSS 9.8
CVE-2026-22778 [CRITICAL] CWE-209 vLLM: vLLM: Remote code execution via invalid image processing in the multimodal endpoint.
vLLM: vLLM: Remote code execution via invalid image processing in the multimodal endpoint.
vLLM is an inference and serving engine for large language models (LLMs). From 0.8.3 to before 0.14.1, when an invalid image is sent to vLLM's multimodal endpoint, PIL throws an error. vLLM returns this error to the client, leaking a heap address. With this leak, we reduce ASLR from 4 billion guesses to ~8 guesses. This vulnerability can be chained a heap overflow with JPEG2000 decoder in OpenCV/FFmpeg to achieve remote code execution. This vulnerability is fixed in 0.14.1.
A flaw was found in vLLM, an inference and serving engine for large language models (LLMs). A remote attacker can exploit this vulnerability by sending a specially crafted video URL to vLLM's multimodal endpoint. This action cau
Ubuntu
FFmpeg vulnerabilities
vendor_ubuntu·2025-10-21·CVSS 7.5
CVE-2023-6603 [HIGH] FFmpeg vulnerabilities
Title: FFmpeg vulnerabilities
Summary: Several security issues were fixed in FFmpeg.
It was discovered that FFmpeg incorrectly handled the return values of
functions in its Firequalizer filter and in the HTTP Live Streaming (HLS)
implementation, leading to a NULL pointer dereference. If a user was
tricked into loading a crafted media file, a remote attacker could
possibly use this issue to make FFmpeg crash, resulting in a denial
of service. (CVE-2023-6603, CVE-2025-10256)
It was discovered that FFmpeg did not enforce an input format before
triggering the HTTP demuxer. A remote attacker could possibly use this
issue to perform a Server-Side Request Forgery (SSRF) attack.
(CVE-2025-6605)
It was discovered that FFmpeg incorrectly handled memory allocation in the
ALS audio decoder. If a u
Debian
CVE-2025-9951: ffmpeg - A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attack...
vendor_debian·2025·CVSS 7.2
CVE-2025-9951 [HIGH] CVE-2025-9951: ffmpeg - A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attack...
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
Scope: local
bookworm: resolved (fixed in 7:5.1.7-0+deb12u1)
bullseye: resolved (fixed in 7:4.3.9-0+deb11u2)
forky: resolved (fixed in 7:7.1.2-1)
sid: resolved (fixed in 7:7.1.2-1)
trixie: resolved (fixed in 7:7.1.2-0+deb13u1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-9951 ffmpeg: heap-based buffer overflow in jpeg2000dec [epel-9]
bugzilla·2025-09-09·CVSS 7.2
CVE-2025-9951 [HIGH] CVE-2025-9951 ffmpeg: heap-based buffer overflow in jpeg2000dec [epel-9]
CVE-2025-9951 ffmpeg: heap-based buffer overflow in jpeg2000dec [epel-9]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
Fixed in 7.1.2 and newer:
https://github.com/FFmpeg/FFmpeg/commit/d141e864f73152e94e0c45cc4abb8c329275c265
https://github.com/FFmpeg/FFmpeg/commit/4c036ec307040469783bab0b7223006c0facec1d
5.1 seems to be affected
Bugzilla
CVE-2025-9951 ffmpeg: heap-based buffer overflow in jpeg2000dec [fedora-42]
bugzilla·2025-09-09·CVSS 7.2
CVE-2025-9951 [HIGH] CVE-2025-9951 ffmpeg: heap-based buffer overflow in jpeg2000dec [fedora-42]
CVE-2025-9951 ffmpeg: heap-based buffer overflow in jpeg2000dec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from
Bugzilla
CVE-2025-9951 qt5-qtwebengine: heap-based buffer overflow in jpeg2000dec [fedora-42]
bugzilla·2025-09-09·CVSS 7.2
CVE-2025-9951 [HIGH] CVE-2025-9951 qt5-qtwebengine: heap-based buffer overflow in jpeg2000dec [fedora-42]
CVE-2025-9951 qt5-qtwebengine: heap-based buffer overflow in jpeg2000dec [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug rep
2025-09-09
Published