CVE-2021-25383
NixOS vulnerability analysis and mitigation

Overview

An improper input validation vulnerability in scmnmfalread() in libsapeextractor library prior to SMR MAY-2021 Release 1 allows attackers to execute arbitrary code on mediaextractor process (MITRE CVE, CISA Bulletin).

Technical details

The vulnerability exists in the scmnmfalread() function within the libsapeextractor library. It has been assigned a CVSS score of 7.5, indicating high severity. The vulnerability stems from improper input validation that could lead to arbitrary code execution in the mediaextractor process (CISA Bulletin).

Impact

If successfully exploited, this vulnerability allows attackers to execute arbitrary code on the mediaextractor process, potentially leading to unauthorized control over the affected component (MITRE CVE).

Mitigation and workarounds

The vulnerability was addressed in the SMR MAY-2021 Release 1 update. Users should ensure their devices are updated to this version or later to mitigate the risk (MITRE CVE).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-14330CRITICAL9.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox:*:*:*:*:esr:*:*:*
NoYesDec 09, 2025
CVE-2025-14329HIGH8.8
  • NixOSNixOS
  • cpe:2.3:a:mozilla:firefox_esr
NoYesDec 09, 2025
CVE-2025-14333HIGH8.1
  • NixOSNixOS
  • firefox-esr
NoYesDec 09, 2025
CVE-2025-14332HIGH7.3
  • NixOSNixOS
  • thunderbird
NoYesDec 09, 2025
CVE-2025-14331MEDIUM6.5
  • NixOSNixOS
  • firefox
NoYesDec 09, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management