Wiz Agents & Workflows are here

CVE-2025-69693
Ffmpeg vulnerability analysis and mitigation

Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid indices 0-63). This results in out-of-bounds array access at lines 1554 (decode_cbp8), 1655 (decode_cbp16), and 1419/1421 (get_c4x4_set), potentially leading to memory disclosure or crash. A previous fix in commit 61cbcaf93f added validation only for intra frames. This vulnerability affects the released versions 8.0 (released 2025-08-22) and 8.0.1 (released 2025-11-20) and is fixed in git master commit 8abeb879df which will be included in FFmpeg 8.1.


SourceNVD

Related Ffmpeg vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-63757HIGH7.5
  • FfmpegFfmpeg
  • ffmpeg-4-libavdevice-devel
NoYesDec 18, 2025
CVE-2025-12343MEDIUM5.5
  • FfmpegFfmpeg
  • ffmpeg
NoYesFeb 18, 2026
CVE-2025-10256MEDIUM5.5
  • FfmpegFfmpeg
  • ffmpeg
NoYesFeb 18, 2026
CVE-2025-69693MEDIUM5.4
  • FfmpegFfmpeg
  • cpe:2.3:a:ffmpeg:ffmpeg
NoYesMar 16, 2026
CVE-2025-7700MEDIUM5.3
  • FfmpegFfmpeg
  • ffmpeg-4-libavformat-devel
NoYesNov 07, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management