ELA-1681-1 ffmpeg security update

multiple vulnerabilities

2026-04-12
Packageffmpeg
Version7:4.1.11-0+deb10u5 (buster)
Related CVEs CVE-2023-6603 CVE-2023-6605 CVE-2025-1594 CVE-2025-7700 CVE-2025-9951 CVE-2025-10256 CVE-2025-63757


Several issues have been found in ffmpeg, a library and tools for transcoding, streaming and playing of multimedia files.

CVE-2023-6603

A flaw was found in FFmpeg’s HLS playlist parsing. This vulnerability allows a denial of service via a maliciously crafted HLS playlist that triggers a null pointer dereference during initialization.

CVE-2023-6605

A flaw was found in FFmpeg’s DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.

CVE-2025-1594

A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

CVE-2025-7700

A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.

CVE-2025-9951

A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.

CVE-2025-10256

A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.

CVE-2025-63757

Integer overflow vulnerability in the yuv2ya16_X_c_template function in libswscale/output.c in FFmpeg 8.0.



For Debian 10 buster, these problems have been fixed in version 7:4.1.11-0+deb10u5.

We recommend that you upgrade your ffmpeg packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.