CVE Vulnerabilities

CVE-2025-22921

NULL Pointer Dereference

Published: Feb 18, 2025 | Modified: Jan 12, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

FFmpeg git-master,N-113007-g8d24a28d06 was discovered to contain a segmentation violation via the component /libavcodec/jpeg2000dec.c.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
FfmpegFfmpeg7.0 (including)7.0 (including)
FfmpegFfmpeg7.0.1 (including)7.0.1 (including)
FfmpegFfmpeg7.0.2 (including)7.0.2 (including)
FfmpegFfmpeg7.0.3 (including)7.0.3 (including)
FfmpegFfmpeg7.1 (including)7.1 (including)
FfmpegFfmpeg7.1-dev (including)7.1-dev (including)
FfmpegFfmpeg7.1.1 (including)7.1.1 (including)
FfmpegFfmpeg7.1.2 (including)7.1.2 (including)
FfmpegFfmpeg7.1.3 (including)7.1.3 (including)
FfmpegFfmpeg7.2-dev (including)7.2-dev (including)
FfmpegFfmpeg8.0 (including)8.0 (including)
FfmpegFfmpeg8.0.1 (including)8.0.1 (including)
FfmpegFfmpeg8.1-dev (including)8.1-dev (including)
FfmpegUbuntudevel*
FfmpegUbuntuesm-apps/jammy*
FfmpegUbuntuesm-apps/noble*
FfmpegUbuntujammy*
FfmpegUbuntunoble*
FfmpegUbuntuoracular*
FfmpegUbuntuplucky*
FfmpegUbuntuquesting*
FfmpegUbuntuupstream*

Potential Mitigations

References