CVE-2025-63757
Ffmpeg vulnerability analysis and mitigation

Overview

CVE-2025-63757 is an integer overflow vulnerability in the yuv2ya16_X_c_template function located in libswscale/output.c in FFmpeg version 8.0. It was published on December 18, 2025, and received an initial analysis by NIST on December 30, 2025. The vulnerability affects FFmpeg 8.0 and carries a CVSS v3.1 base score of 7.5 (High), assessed by CISA-ADP (NVD, Feedly).

Technical details

The root cause is an integer overflow or wraparound (CWE-190) in the yuv2ya16_X_c_template function within FFmpeg's libswscale/output.c, which handles YUV-to-YA16 pixel format conversion during video scaling operations. When processing specially crafted media input, an arithmetic operation on an integer value can overflow, potentially leading to incorrect memory operations such as out-of-bounds writes or reads. The attack vector is network-based, requiring no authentication or user interaction, making it exploitable by a remote unauthenticated attacker who can supply malicious media content to an application using FFmpeg 8.0. A patch pull request has been submitted to the FFmpeg repository (FFmpeg PR, GitHub Gist).

Impact

Successful exploitation of this vulnerability results in a denial-of-service condition, as the CVSS vector indicates high availability impact with no confidentiality or integrity impact. An attacker can cause a crash or abnormal termination of any application that uses FFmpeg 8.0 to process untrusted media files, such as video transcoding services, media players, or streaming platforms. The scope is limited to the affected process, but in server-side deployments processing user-supplied content, this could result in sustained service disruption (NVD).

Exploitation steps

  1. Identify target: Locate services or applications that use FFmpeg 8.0 for media processing, such as video transcoding APIs, streaming servers, or media conversion tools that accept user-supplied files.
  2. Craft malicious media file: Create a specially crafted video or image file that triggers the integer overflow in the yuv2ya16_X_c_template function during YUV-to-YA16 color space conversion in libswscale/output.c.
  3. Submit malicious input: Upload or stream the crafted media file to the target application, causing FFmpeg to process it through the vulnerable libswscale scaling path.
  4. Trigger overflow: The integer overflow occurs during pixel format conversion, potentially causing a crash (denial of service) of the FFmpeg process or the hosting application (NVD, FFmpeg PR).

Indicators of compromise

  • Logs: Application or system logs showing unexpected crashes or segmentation faults in FFmpeg processes, particularly during video scaling or format conversion operations involving YUV/YA16 pixel formats.
  • Process: Abnormal termination of FFmpeg worker processes (ffmpeg, ffprobe) when processing specific media files; repeated restarts of media processing services.
  • File System: Presence of unusual or malformed media files (e.g., crafted .mp4, .mkv, or image files) submitted by external users that consistently cause FFmpeg crashes.

Mitigation and workarounds

Users should upgrade FFmpeg from version 8.0 to a patched release once available, as a fix has been submitted via pull request to the FFmpeg repository (FFmpeg PR). Debian LTS users can apply the security update referenced in the Debian LTS announcement (Debian LTS), and Ubuntu users should apply the update referenced in USN-7982-1 (Ubuntu Advisory). As a workaround, restrict the processing of untrusted or user-supplied media files through FFmpeg 8.0, or sandbox FFmpeg processes to limit the impact of a crash. Monitor the official FFmpeg security page for patch releases (FFmpeg Security).

Community reactions

The vulnerability has been picked up by Linux distribution security teams, with Debian LTS issuing advisory DLA-4440-1 and Ubuntu issuing USN-7982-1 to address FFmpeg vulnerabilities including CVE-2025-63757 (Debian LTS, Ubuntu Advisory). SUSE has also issued related security updates for FFmpeg (Feedly). No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking coverage.

Additional resources


SourceThis report was generated using AI

Related Ffmpeg vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-66040HIGH8.7
  • Ffmpeg logoFfmpeg
  • cpe:2.3:a:ffmpeg:ffmpeg
NoNoJul 24, 2026
CVE-2026-66039HIGH8.7
  • Ffmpeg logoFfmpeg
  • cpe:2.3:a:ffmpeg:ffmpeg
NoNoJul 24, 2026
CVE-2026-66041HIGH7.7
  • Ffmpeg logoFfmpeg
  • cpe:2.3:a:ffmpeg:ffmpeg
NoNoJul 24, 2026
CVE-2026-66038HIGH7.1
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoNoJul 24, 2026
CVE-2026-66037HIGH7.1
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoNoJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management