USN-7538-1: FFmpeg vulnerabilities

Publication date

28 May 2025

Overview

Several security issues were fixed in FFmpeg.


Packages

  • ffmpeg - Tools for transcoding, streaming and playing of multimedia files

Details

Simcha Kosman discovered that FFmpeg did not correctly handle certain
return values. An attacker could possibly use this issue to leak
sensitive information. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS
and Ubuntu 24.10. (CVE-2025-0518)

It was discovered that FFmpeg did not correctly handle certain memory
operations. A remote attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. This issue only affected
Ubuntu 24.10. (CVE-2025-1816)

It was discovered that FFmpeg contained a reachable assertion, which
could lead to a failure when processing certain AAC files. If a user or
automated system were tricked into opening a specially crafted AAC file,
an attacker could possibly use this issue to cause a denial of service.
This issue only affected...

Simcha Kosman discovered that FFmpeg did not correctly handle certain
return values. An attacker could possibly use this issue to leak
sensitive information. This issue only affected Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS
and Ubuntu 24.10. (CVE-2025-0518)

It was discovered that FFmpeg did not correctly handle certain memory
operations. A remote attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. This issue only affected
Ubuntu 24.10. (CVE-2025-1816)

It was discovered that FFmpeg contained a reachable assertion, which
could lead to a failure when processing certain AAC files. If a user or
automated system were tricked into opening a specially crafted AAC file,
an attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 16.04 LTS, Ubuntu 18.04 LTS,
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, Ubuntu 24.04 LTS and Ubuntu 24.10.
(CVE-2025-22919)

It was discovered that FFmpeg did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial
of service. This issue only affected Ubuntu 22.04 LTS, Ubuntu 24.04 LTS,
Ubuntu 24.10 and Ubuntu 25.04. (CVE-2025-22921)

It was discovered that FFmpeg did not correctly handle certain memory
operations. An attacker could possibly use this issue to cause a denial
of service or execute arbitrary code. This issue only affected
Ubuntu 24.04 LTS, Ubuntu 24.10 and Ubuntu 25.04. (CVE-2025-25473)


Update instructions

After a standard system update you need to restart FFmpeg to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
25.04 plucky ffmpeg –  7:7.1.1-1ubuntu1.1
libavcodec-extra61 –  7:7.1.1-1ubuntu1.1
libavcodec61 –  7:7.1.1-1ubuntu1.1
libavdevice61 –  7:7.1.1-1ubuntu1.1
libavfilter-extra10 –  7:7.1.1-1ubuntu1.1
libavfilter10 –  7:7.1.1-1ubuntu1.1
libavformat-extra61 –  7:7.1.1-1ubuntu1.1
libavformat61 –  7:7.1.1-1ubuntu1.1
libavutil59 –  7:7.1.1-1ubuntu1.1
libpostproc58 –  7:7.1.1-1ubuntu1.1
libswresample5 –  7:7.1.1-1ubuntu1.1
libswscale8 –  7:7.1.1-1ubuntu1.1
24.10 oracular ffmpeg –  7:7.0.2-3ubuntu1.1
libavcodec-extra61 –  7:7.0.2-3ubuntu1.1
libavcodec61 –  7:7.0.2-3ubuntu1.1
libavdevice61 –  7:7.0.2-3ubuntu1.1
libavfilter-extra10 –  7:7.0.2-3ubuntu1.1
libavfilter10 –  7:7.0.2-3ubuntu1.1
libavformat-extra61 –  7:7.0.2-3ubuntu1.1
libavformat61 –  7:7.0.2-3ubuntu1.1
libavutil59 –  7:7.0.2-3ubuntu1.1
libpostproc58 –  7:7.0.2-3ubuntu1.1
libswresample5 –  7:7.0.2-3ubuntu1.1
libswscale8 –  7:7.0.2-3ubuntu1.1
24.04 noble ffmpeg –  7:6.1.1-3ubuntu5+esm3  
libavcodec-extra60 –  7:6.1.1-3ubuntu5+esm3  
libavcodec60 –  7:6.1.1-3ubuntu5+esm3  
libavdevice60 –  7:6.1.1-3ubuntu5+esm3  
libavfilter-extra9 –  7:6.1.1-3ubuntu5+esm3  
libavfilter9 –  7:6.1.1-3ubuntu5+esm3  
libavformat-extra60 –  7:6.1.1-3ubuntu5+esm3  
libavformat60 –  7:6.1.1-3ubuntu5+esm3  
libavutil58 –  7:6.1.1-3ubuntu5+esm3  
libpostproc57 –  7:6.1.1-3ubuntu5+esm3  
libswresample4 –  7:6.1.1-3ubuntu5+esm3  
libswscale7 –  7:6.1.1-3ubuntu5+esm3  
22.04 jammy ffmpeg –  7:4.4.2-0ubuntu0.22.04.1+esm7  
libavcodec-extra58 –  7:4.4.2-0ubuntu0.22.04.1+esm7  
libavcodec58 –  7:4.4.2-0ubuntu0.22.04.1+esm7  
libavdevice58 –  7:4.4.2-0ubuntu0.22.04.1+esm7  
libavfilter-extra7 –  7:4.4.2-0ubuntu0.22.04.1+esm7  
libavfilter7 –  7:4.4.2-0ubuntu0.22.04.1+esm7  
libavformat-extra58 –  7:4.4.2-0ubuntu0.22.04.1+esm7  
libavformat58 –  7:4.4.2-0ubuntu0.22.04.1+esm7  
libavutil56 –  7:4.4.2-0ubuntu0.22.04.1+esm7  
libpostproc55 –  7:4.4.2-0ubuntu0.22.04.1+esm7  
libswresample3 –  7:4.4.2-0ubuntu0.22.04.1+esm7  
libswscale5 –  7:4.4.2-0ubuntu0.22.04.1+esm7  
20.04 focal ffmpeg –  7:4.2.7-0ubuntu0.1+esm8  
libavcodec-extra58 –  7:4.2.7-0ubuntu0.1+esm8  
libavcodec58 –  7:4.2.7-0ubuntu0.1+esm8  
libavdevice58 –  7:4.2.7-0ubuntu0.1+esm8  
libavfilter-extra7 –  7:4.2.7-0ubuntu0.1+esm8  
libavfilter7 –  7:4.2.7-0ubuntu0.1+esm8  
libavformat58 –  7:4.2.7-0ubuntu0.1+esm8  
libavresample4 –  7:4.2.7-0ubuntu0.1+esm8  
libavutil56 –  7:4.2.7-0ubuntu0.1+esm8  
libpostproc55 –  7:4.2.7-0ubuntu0.1+esm8  
libswresample3 –  7:4.2.7-0ubuntu0.1+esm8  
libswscale5 –  7:4.2.7-0ubuntu0.1+esm8  
18.04 bionic ffmpeg –  7:3.4.11-0ubuntu0.1+esm8  
libavcodec-extra57 –  7:3.4.11-0ubuntu0.1+esm8  
libavcodec57 –  7:3.4.11-0ubuntu0.1+esm8  
libavdevice57 –  7:3.4.11-0ubuntu0.1+esm8  
libavfilter-extra6 –  7:3.4.11-0ubuntu0.1+esm8  
libavfilter6 –  7:3.4.11-0ubuntu0.1+esm8  
libavformat57 –  7:3.4.11-0ubuntu0.1+esm8  
libavresample3 –  7:3.4.11-0ubuntu0.1+esm8  
libavutil55 –  7:3.4.11-0ubuntu0.1+esm8  
libpostproc54 –  7:3.4.11-0ubuntu0.1+esm8  
libswresample2 –  7:3.4.11-0ubuntu0.1+esm8  
libswscale4 –  7:3.4.11-0ubuntu0.1+esm8  
16.04 xenial ffmpeg –  7:2.8.17-0ubuntu0.1+esm10  
libav-tools –  7:2.8.17-0ubuntu0.1+esm10  
libavcodec-ffmpeg-extra56 –  7:2.8.17-0ubuntu0.1+esm10  
libavcodec-ffmpeg56 –  7:2.8.17-0ubuntu0.1+esm10  
libavdevice-ffmpeg56 –  7:2.8.17-0ubuntu0.1+esm10  
libavfilter-ffmpeg5 –  7:2.8.17-0ubuntu0.1+esm10  
libavformat-ffmpeg56 –  7:2.8.17-0ubuntu0.1+esm10  
libavresample-ffmpeg2 –  7:2.8.17-0ubuntu0.1+esm10  
libavutil-ffmpeg54 –  7:2.8.17-0ubuntu0.1+esm10  
libpostproc-ffmpeg53 –  7:2.8.17-0ubuntu0.1+esm10  
libswresample-ffmpeg1 –  7:2.8.17-0ubuntu0.1+esm10  
libswscale-ffmpeg3 –  7:2.8.17-0ubuntu0.1+esm10  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›