
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-63757 is an integer overflow vulnerability in the yuv2ya16_X_c_template function located in libswscale/output.c in FFmpeg version 8.0. It was published on December 18, 2025, and received an initial analysis by NIST on December 30, 2025. The vulnerability affects FFmpeg 8.0 and carries a CVSS v3.1 base score of 7.5 (High), assessed by CISA-ADP (NVD, Feedly).
The root cause is an integer overflow or wraparound (CWE-190) in the yuv2ya16_X_c_template function within FFmpeg's libswscale/output.c, which handles YUV-to-YA16 pixel format conversion during video scaling operations. When processing specially crafted media input, an arithmetic operation on an integer value can overflow, potentially leading to incorrect memory operations such as out-of-bounds writes or reads. The attack vector is network-based, requiring no authentication or user interaction, making it exploitable by a remote unauthenticated attacker who can supply malicious media content to an application using FFmpeg 8.0. A patch pull request has been submitted to the FFmpeg repository (FFmpeg PR, GitHub Gist).
Successful exploitation of this vulnerability results in a denial-of-service condition, as the CVSS vector indicates high availability impact with no confidentiality or integrity impact. An attacker can cause a crash or abnormal termination of any application that uses FFmpeg 8.0 to process untrusted media files, such as video transcoding services, media players, or streaming platforms. The scope is limited to the affected process, but in server-side deployments processing user-supplied content, this could result in sustained service disruption (NVD).
yuv2ya16_X_c_template function during YUV-to-YA16 color space conversion in libswscale/output.c.libswscale scaling path.ffmpeg, ffprobe) when processing specific media files; repeated restarts of media processing services..mp4, .mkv, or image files) submitted by external users that consistently cause FFmpeg crashes.Users should upgrade FFmpeg from version 8.0 to a patched release once available, as a fix has been submitted via pull request to the FFmpeg repository (FFmpeg PR). Debian LTS users can apply the security update referenced in the Debian LTS announcement (Debian LTS), and Ubuntu users should apply the update referenced in USN-7982-1 (Ubuntu Advisory). As a workaround, restrict the processing of untrusted or user-supplied media files through FFmpeg 8.0, or sandbox FFmpeg processes to limit the impact of a crash. Monitor the official FFmpeg security page for patch releases (FFmpeg Security).
The vulnerability has been picked up by Linux distribution security teams, with Debian LTS issuing advisory DLA-4440-1 and Ubuntu issuing USN-7982-1 to address FFmpeg vulnerabilities including CVE-2025-63757 (Debian LTS, Ubuntu Advisory). SUSE has also issued related security updates for FFmpeg (Feedly). No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."