AI Security Summit: Join Figma, Perplexity & Wiz. [Register]

CVE-2025-59728
Ffmpeg vulnerability analysis and mitigation

Overview

CVE-2025-59728 is an out-of-bounds NUL-byte write vulnerability in FFmpeg's MPEG-DASH manifest handling that can lead to memory corruption. The flaw exists in versions prior to 8.0, including the 7.1.1 release line, and was publicly disclosed on October 6, 2025. It carries a CVSS v4.0 base score of 8.7 (High), assigned by Google (ENISA EUVD, Feedly).

Technical details

The root cause is an out-of-bounds write (CWE-787) occurring during content path calculation when parsing MPEG-DASH manifests. Specifically, xmlNodeGetContent returns a buffer allocated via strdup to exactly match the string length. If the last non-NUL byte is not /, FFmpeg appends / in-place at that position, writing two bytes — the / character and a NUL terminator — starting at the last valid byte, causing the NUL byte to land one byte past the end of the allocated buffer. Exploitation requires adjacent network access, low privileges, and high attack complexity, with no user interaction needed (ENISA EUVD, Google Issue Tracker).

Impact

Successful exploitation can result in high confidentiality and integrity impacts on both the vulnerable component and any dependent system components, while availability is not directly affected per the CVSS v4.0 assessment. The off-by-one NUL-byte write can corrupt adjacent heap memory, potentially enabling an attacker to influence program control flow, leak sensitive data, or achieve code execution depending on heap layout. The vulnerability affects any application or service using FFmpeg versions before 8.0 to process MPEG-DASH content (ENISA EUVD, Feedly).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-59728. The EPSS score is approximately 0.022% (0.000220), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Detection signatures have been added by Qualys and Nessus, suggesting active scanner coverage (Feedly).

Mitigation and workarounds

The vendor recommends upgrading FFmpeg to version 8.0 or later, which resolves the out-of-bounds write in MPEG-DASH manifest handling. Linux distribution vendors including SUSE, Ubuntu, and Mageia have released updated packages addressing this CVE. Users unable to upgrade immediately should restrict processing of untrusted or externally sourced MPEG-DASH manifests as a temporary mitigation (ENISA EUVD, Ubuntu Advisory, SUSE Advisory).

Community reactions

The vulnerability received coverage from Linux security news outlets including LinuxSecurity.com and Pro-Linux.de following distribution advisories from SUSE and Ubuntu. Community discussion has been limited, consistent with the low EPSS score and absence of public exploit code. No notable researcher commentary or vendor statements beyond the upstream fix recommendation have been identified (Pro-Linux, LinuxSecurity SUSE).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Alpine

Fixed

edge

ffmpeg: 8.0-r0

Fixed

v3.23

ffmpeg: 8.0-r0

Fixed

SourceThis report was generated using AI

Related Ffmpeg vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-30754HIGH8.8
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 08, 2026
CVE-2026-90816MEDIUM5.3
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 14, 2026
CVE-2026-52297LOW2.9
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 13, 2026
CVE-2026-52296LOW2.9
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 13, 2026
CVE-2026-90815LOW2.1
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management