CVE-2025-25467

EUVD-2025-4692
Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 65%
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libav
focal
dne
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
trusty
needs-triage
x264
bionic
needed
focal
needed
jammy
needed
noble
needed
oracular
ignored
plucky
ignored
questing
needed
trusty
needed
xenial
needed
ffmpeg
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
oracular
ignored
plucky
ignored
questing
deferred
xenial
deferred