A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.

Project Subscriptions

No data.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4440-1 ffmpeg security update
Debian DSA Debian DSA DSA-6007-1 ffmpeg security update
Fixes

Solution

No solution given by the vendor.


Workaround

No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

History

Wed, 18 Feb 2026 20:45:00 +0000

Type Values Removed Values Added
Description A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.
Title Ffmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c)
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-02-18T20:26:46.867Z

Reserved: 2025-09-11T06:11:12.091Z

Link: CVE-2025-10256

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-18T21:16:20.183

Modified: 2026-02-18T21:16:20.183

Link: CVE-2025-10256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses