PT-2025-7626 · Openh264+3 · Openh264+3

Andrew Calvano

+1

·

Published

2025-02-20

·

Updated

2025-10-10

·

CVE-2025-27091

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenH264 versions 2.5.0 and earlier
Description OpenH264 contains a heap overflow vulnerability in its decoding functions. This issue is due to a race condition occurring between a Sequence Parameter Set (SPS) memory allocation and a subsequent non-Instantaneous Decoder Refresh (non-IDR) Network Abstraction Layer (NAL) unit memory usage. An attacker can exploit this by crafting a malicious bitstream and tricking a user into processing a video containing it. Successful exploitation could lead to a crash or potentially allow the attacker to execute arbitrary commands. Both Scalable Video Coding (SVC) and Advanced Video Coding (AVC) modes are affected.
Recommendations Upgrade OpenH264 to version 2.6.0 or later.

Exploit

Fix

RCE

Memory Corruption

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-02022
CVE-2025-27091
DSA-5870-1
GHSA-5PMW-9J92-3C4C
GHSA-M99Q-5J7X-7M9X
RUSTSEC-2025-0008

Affected Products

Astra Linux
Debian
Openh264
Red Os