CVE-2025-9951

HIGH

FFmpeg - Buffer Overflow

Title source: llm
STIX 2.1

Description

A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.

References (1)

Core 1

Scores

CVSS v4 7.2
EPSS 0.0056
EPSS Percentile 68.3%
CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-122
Status published
Products (1)
FFmpeg/FFmpeg < 8.0
Published Sep 09, 2025
Tracked Since Feb 18, 2026