CVE-2025-7700

A flaw was found in FFmpegs ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
redhatCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA-ADPADP
---
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Debian logo
Debian Releases
Debian Product
Codename
ffmpeg
bullseye
postponed
bullseye (security)
vulnerable
bookworm
7:5.1.7-0+deb12u1
fixed
bookworm (security)
7:5.1.7-0+deb12u1
fixed
trixie
vulnerable
trixie (security)
7:7.1.2-0+deb13u1
fixed
forky
7:7.1.2-1
fixed
sid
7:7.1.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ffmpeg
plucky
needed
noble
needed
jammy
needed
focal
needed
bionic
needed
xenial
needed
libav
plucky
dne
noble
dne
jammy
dne
trusty
needs-triage