FFmpeg is a complete and free Internet live audio and video broadcasting solution for Linux/Unix. It also includes a digital VCR. It can encode in real time in many formats including MPEG1 audio and video, MPEG4, h263, ac3, asf, avi, real, mjpeg, and flash.
Security Fix(es):
Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C .
This issue affects FFmpeg: 7.1.
Issue was fixed: https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a
https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman(CVE-2025-0518)
A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/affirequalizer.c) due to a missing check on the return value of avmallocarray() in the configinput() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.(CVE-2025-10256)
A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ffaacsearchfortns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.(CVE-2025-1594)
A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds checks, leading to a heap out-of-bounds write. Successful exploitation can result in a denial of service (DoS) due to an application crash, and potentially lead to arbitrary code execution.(CVE-2026-6385)
{
"severity": "High"
}{
"x86_64": [
"ffmpeg-6.1.1-35.oe2403sp4.x86_64.rpm",
"ffmpeg-debuginfo-6.1.1-35.oe2403sp4.x86_64.rpm",
"ffmpeg-debugsource-6.1.1-35.oe2403sp4.x86_64.rpm",
"ffmpeg-devel-6.1.1-35.oe2403sp4.x86_64.rpm",
"ffmpeg-libs-6.1.1-35.oe2403sp4.x86_64.rpm",
"libavdevice-6.1.1-35.oe2403sp4.x86_64.rpm"
],
"src": [
"ffmpeg-6.1.1-35.oe2403sp4.src.rpm"
],
"aarch64": [
"ffmpeg-6.1.1-35.oe2403sp4.aarch64.rpm",
"ffmpeg-debuginfo-6.1.1-35.oe2403sp4.aarch64.rpm",
"ffmpeg-debugsource-6.1.1-35.oe2403sp4.aarch64.rpm",
"ffmpeg-devel-6.1.1-35.oe2403sp4.aarch64.rpm",
"ffmpeg-libs-6.1.1-35.oe2403sp4.aarch64.rpm",
"libavdevice-6.1.1-35.oe2403sp4.aarch64.rpm"
]
}