CVE-2025-25467

EUVD-2025-4692
Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 39%
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ffmpeg
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
oracular
ignored
plucky
ignored
questing
deferred
resolute
deferred
xenial
ignored
libav
focal
dne
jammy
dne
noble
dne
oracular
dne
plucky
dne
questing
dne
resolute
dne
trusty
needs-triage
x264
bionic
deferred
focal
deferred
jammy
deferred
noble
deferred
oracular
ignored
plucky
ignored
questing
deferred
resolute
deferred
trusty
deferred
xenial
ignored