A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.
Project Subscriptions
No data.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4440-1 | ffmpeg security update |
Debian DSA |
DSA-6007-1 | ffmpeg security update |
Fixes
Solution
No solution given by the vendor.
Workaround
No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.
References
History
Wed, 18 Feb 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service. | |
| Title | Ffmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c) | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2026-02-18T20:26:46.867Z
Reserved: 2025-09-11T06:11:12.091Z
Link: CVE-2025-10256
No data.
Status : Received
Published: 2026-02-18T21:16:20.183
Modified: 2026-02-18T21:16:20.183
Link: CVE-2025-10256
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA