
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59728 is an out-of-bounds NUL-byte write vulnerability in FFmpeg's MPEG-DASH manifest handling that can lead to memory corruption. The flaw exists in versions prior to 8.0, including the 7.1.1 release line, and was publicly disclosed on October 6, 2025. It carries a CVSS v4.0 base score of 8.7 (High), assigned by Google (ENISA EUVD, Feedly).
The root cause is an out-of-bounds write (CWE-787) occurring during content path calculation when parsing MPEG-DASH manifests. Specifically, xmlNodeGetContent returns a buffer allocated via strdup to exactly match the string length. If the last non-NUL byte is not /, FFmpeg appends / in-place at that position, writing two bytes — the / character and a NUL terminator — starting at the last valid byte, causing the NUL byte to land one byte past the end of the allocated buffer. Exploitation requires adjacent network access, low privileges, and high attack complexity, with no user interaction needed (ENISA EUVD, Google Issue Tracker).
Successful exploitation can result in high confidentiality and integrity impacts on both the vulnerable component and any dependent system components, while availability is not directly affected per the CVSS v4.0 assessment. The off-by-one NUL-byte write can corrupt adjacent heap memory, potentially enabling an attacker to influence program control flow, leak sensitive data, or achieve code execution depending on heap layout. The vulnerability affects any application or service using FFmpeg versions before 8.0 to process MPEG-DASH content (ENISA EUVD, Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-59728. The EPSS score is approximately 0.022% (0.000220), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Detection signatures have been added by Qualys and Nessus, suggesting active scanner coverage (Feedly).
The vendor recommends upgrading FFmpeg to version 8.0 or later, which resolves the out-of-bounds write in MPEG-DASH manifest handling. Linux distribution vendors including SUSE, Ubuntu, and Mageia have released updated packages addressing this CVE. Users unable to upgrade immediately should restrict processing of untrusted or externally sourced MPEG-DASH manifests as a temporary mitigation (ENISA EUVD, Ubuntu Advisory, SUSE Advisory).
The vulnerability received coverage from Linux security news outlets including LinuxSecurity.com and Pro-Linux.de following distribution advisories from SUSE and Ubuntu. Community discussion has been limited, consistent with the low EPSS score and absence of public exploit code. No notable researcher commentary or vendor statements beyond the upstream fix recommendation have been identified (Pro-Linux, LinuxSecurity SUSE).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
ffmpeg
devel
ffmpeg
focal (esm-apps)
ffmpeg: 7:4.2.7-0ubuntu0.1+esm12
jammy
ffmpeg
jammy (esm-apps)
ffmpeg: 7:4.4.2-0ubuntu0.22.04.1+esm11
noble
ffmpeg
noble (esm-apps)
ffmpeg: 7:6.1.1-3ubuntu5+esm7
questing
ffmpeg: 7:7.1.1-1ubuntu4.2
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."