CVE-2025-14569

Source
https://cve.org/CVERecord?id=CVE-2025-14569
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14569.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-14569
Published
2025-12-12T19:16:01.610Z
Modified
2026-03-13T22:13:34.023811Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
[none]
Details

A vulnerability was detected in ggml-org whisper.cpp up to 1.8.2. Affected is the function readaudiodata of the file /whisper.cpp/examples/common-whisper.cpp. The manipulation results in use after free. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References

Affected packages

Git /

Affected ranges

Database specific

unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "an"
            }
        ]
    }
]
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14569.json"