PT-2025-7657 · FFmpeg+5 · Ffmpeg+5

0X20Z

·

Published

2025-01-14

·

Updated

2026-05-29

·

CVE-2025-1594

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg versions up to 7.1
Description A critical vulnerability was found in FFmpeg, affecting the function ff aac search for tns of the file libavcodec/aacenc tns.c of the component AAC Encoder. The manipulation leads to a stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Recommendations For FFmpeg versions up to 7.1, update to a version later than 7.1 to resolve the issue. As a temporary workaround, consider disabling the ff aac search for tns function until a patch is available. Restrict access to the vulnerable AAC Encoder component to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Stack Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-11468
CVE-2025-1594
DSA-6007-1
DSA-6079-1
OPENSUSE-SU-2026:10866-1
OPENSUSE-SU-2026:10867-1
OPENSUSE-SU-2026:10890-1
USN-7738-1

Affected Products

Astra Linux
Debian
Ffmpeg
Linuxmint
Red Os
Ubuntu