CVE-2025-59731

MEDIUM

FFmpeg 7.1.1-8.0 - Out-of-bounds Write in OpenEXR DWAA/DWAB Compression

Title source: llm
STIX 2.1

Description

When decoding an OpenEXR file that uses DWAA or DWAB compression, the specified raw length of run-length-encoded data is not checked when using it to calculate the output data. We read rle_raw_size from the input file at [0], we decompress and decode into the buffer td->rle_raw_data of size rle_raw_size at [1], and then at [2] we will access entries in this buffer up to (td->xsize - 1) * (td->ysize - 1) + rle_raw_size / 2, which may exceed rle_raw_size. We recommend upgrading to version 8.0 or beyond.

References (1)

Core 1
Core References

Scores

CVSS v4 6.9
EPSS 0.0002
EPSS Percentile 5.5%
CVSS:4.0/AV:A/AC:H/AT:N/PR:L/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (2)
FFmpeg/FFmpeg 7.1.1 - 8.0
FFmpeg/FFmpeg 9a32b863074ed4140141e0d3613905c6f1fe61c5 - 8.0
Published Oct 06, 2025
Tracked Since Feb 18, 2026