CVE-2025-7700

EUVD-2025-38295
A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
redhatCNA
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 12%
Debian logo
Debian Releases
Debian Product
Codename
ffmpeg
bookworm
7:5.1.8-0+deb12u1
fixed
bookworm (security)
7:5.1.8-0+deb12u1
fixed
bullseye
vulnerable
bullseye (security)
7:4.3.9-0+deb11u2
fixed
forky
7:8.0.1-3
fixed
sid
7:8.0.1-3
fixed
trixie
7:7.1.3-0+deb13u1
fixed
trixie (security)
7:7.1.3-0+deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ffmpeg
bionic
ignored
focal
ignored
jammy
needed
noble
Fixed 7:6.1.1-3ubuntu5+esm6
released
plucky
Fixed 7:7.1.1-1ubuntu1.3
released
questing
Fixed 7:7.1.1-1ubuntu4.1
released
xenial
not-affected
libav
jammy
dne
noble
dne
plucky
dne
questing
dne
trusty
needs-triage