CVE Vulnerabilities

CVE-2025-7700

NULL Pointer Dereference

Published: Nov 07, 2025 | Modified: Nov 12, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
5.3 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Ffmpeg Ubuntu esm-apps/bionic *
Ffmpeg Ubuntu esm-apps/focal *
Ffmpeg Ubuntu esm-apps/jammy *
Ffmpeg Ubuntu esm-apps/noble *
Ffmpeg Ubuntu jammy *
Ffmpeg Ubuntu noble *
Ffmpeg Ubuntu plucky *
Ffmpeg Ubuntu questing *
Ffmpeg Ubuntu upstream *

Potential Mitigations

References