CVE-2025-59732

EUVD-2025-32179
When decoding an OpenEXR file that uses DWAA or DWAB compression, there's an implicit assumption that the height and width are divisible by 8.

If the height or width of the image is not divisible by 8, the copy loops at [0] and [1] will continue to write until the next multiple of 8.

The buffer td->uncompressed_data is allocated in decode_block based on the precise height and width of the image, so the "rounded-up" multiple of 8 in the copy loop can exceed the buffer bounds, and the write block starting at [2] can corrupt following heap memory.



We recommend upgrading to version 8.0 or beyond.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
GoogleCNA
8.7 HIGH
ADJACENT
HIGH
NONE
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 6.05%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
ffmpegffmpeg
𝑥
< 8.0
CNA
ffmpegffmpeg
7.1.1 ≤
𝑥
< 8.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
ffmpeg
bookworm
7:5.1.9-0+deb12u1
fixed
bookworm (security)
7:5.1.9-0+deb12u1
fixed
bullseye
7:4.3.7-0+deb11u1
fixed
bullseye (security)
7:4.3.9-0+deb11u2
fixed
forky
7:8.1.2-2
fixed
sid
7:8.1.2-2
fixed
trixie
7:7.1.5-0+deb13u1
fixed
trixie (security)
7:7.1.5-0+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ffmpeg
bionic
not-affected
focal
not-affected
jammy
Fixed 7:4.4.2-0ubuntu0.22.04.1+esm11
released
noble
Fixed 7:6.1.1-3ubuntu5+esm7
released
plucky
ignored
questing
Fixed 7:7.1.1-1ubuntu4.2
released
resolute
not-affected
xenial
not-affected
libav
jammy
dne
noble
dne
plucky
dne
questing
dne
resolute
dne
trusty
needs-triage