CVE-2025-7700

A flaw was found in FFmpegs ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
redhatCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA-ADPADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 9%
Debian logo
Debian Releases
Debian Product
Codename
ffmpeg
bullseye
postponed
bullseye (security)
vulnerable
bookworm
7:5.1.7-0+deb12u1
fixed
bookworm (security)
7:5.1.8-0+deb12u1
fixed
trixie
7:7.1.2-0+deb13u1
fixed
trixie (security)
7:7.1.3-0+deb13u1
fixed
forky
7:7.1.3-1
fixed
sid
7:8.0.1-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ffmpeg
questing
Fixed 7:7.1.1-1ubuntu4.1
released
plucky
Fixed 7:7.1.1-1ubuntu1.3
released
noble
Fixed 7:6.1.1-3ubuntu5+esm6
released
jammy
needed
focal
ignored
bionic
ignored
xenial
not-affected
libav
questing
dne
plucky
dne
noble
dne
jammy
dne
trusty
needs-triage