NULL pointer dereference in FFmpeg - CVE-2025-10256

 

NULL pointer dereference in FFmpeg - CVE-2025-10256

Published: October 27, 2025


Vulnerability identifier: #VU117663
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2025-10256
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability: No public exploit available
Affected software:
FFmpeg
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Workstation Extension 15
Desktop Applications Module
SUSE Package Hub 15
Ubuntu
libpostproc54-debuginfo
libavresample-devel
libavformat-devel
libavcodec-devel
libpostproc-devel
libswresample2
libswscale4-debuginfo
libavutil-devel
libavcodec57-debuginfo
libswresample-devel
libavcodec57
libswresample2-debuginfo
libswscale-devel
libpostproc54
libswscale4
libavutil55-debuginfo
libavutil55
libavfilter6-debuginfo
libavformat57
ffmpeg-debugsource
libavresample3-debuginfo
libavresample3
ffmpeg-debuginfo
libavfilter6
libavdevice57-debuginfo
libavformat57-debuginfo
ffmpeg
libavdevice57
ffmpeg (Ubuntu package)

Detailed vulnerability description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error when parsing HLS playlists. A remote attacker can pass specially crafted HLS playlist to the application and crash the application.


How to mitigate CVE-2025-10256

Install update from vendor's website.

Sources