#VU107134 Reachable assertion in FFmpeg - CVE-2025-22919
Published: April 8, 2025
FFmpeg
ffmpeg.sourceforge.net
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a reachable assertion within the init_audio() function in libavfilter/buffersrc.c. A remote attacker can pass a specially crafted AAC file to the application, trigger an assertion failure and perform a denial of service (DoS) attack.