A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.
Advisories
Source ID Title
Debian DSA Debian DSA DSA-5985-1 ffmpeg security update
Debian DSA Debian DSA DSA-6007-1 ffmpeg security update
Fixes

Solution

No solution given by the vendor.


Workaround

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Users are strongly encouraged to apply vendor-supplied updates or patches as they become available to address this vulnerability.

History

Fri, 07 Nov 2025 19:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE. A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.
Title FFmpeg: NULL Pointer Dereference in FFmpeg ALS Decoder (libavcodec/alsdec.c) Ffmpeg: null pointer dereference in ffmpeg als decoder (libavcodec/alsdec.c)
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Jul 2025 12:15:00 +0000

Type Values Removed Values Added
Description No description is available for this CVE.
Title FFmpeg: NULL Pointer Dereference in FFmpeg ALS Decoder (libavcodec/alsdec.c)
Weaknesses CWE-476
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2025-11-07T19:08:06.222Z

Reserved: 2025-07-16T05:12:48.951Z

Link: CVE-2025-7700

cve-icon Vulnrichment

Updated: 2025-11-07T19:08:01.227Z

cve-icon NVD

Status : Received

Published: 2025-11-07T19:16:27.923

Modified: 2025-11-07T19:16:27.923

Link: CVE-2025-7700

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-07-15T00:00:00Z

Links: CVE-2025-7700 - Bugzilla

cve-icon OpenCVE Enrichment

No data.