A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/22xxx/CVE-2025-22920.json",
"cna_assigner": "mitre"
}"2026-08-17T04:12:29Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22920.json"
[
{
"deprecated": false,
"target": {
"file": "libavformat/dump.c",
"function": "dump_stream_group"
},
"id": "CVE-2025-22920-032c8ef3",
"signature_version": "v1",
"digest": {
"function_hash": "70396055671749122657989014028539752311",
"length": 5658.0
},
"source": "https://git.ffmpeg.org/ffmpeg.git@4bf784c0e5615c3f934e677d5de093a8be7da7ae",
"signature_type": "Function"
},
{
"deprecated": false,
"target": {
"file": "libavformat/dump.c"
},
"id": "CVE-2025-22920-2feb5b98",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"312459793511290586234133337784754532888",
"183607684213541125376994226150133169831",
"30403947470803405872314873576994182819",
"101234647407442325980436209429316218007",
"241933069208255574297658600788560652581"
]
},
"source": "https://git.ffmpeg.org/ffmpeg.git@4bf784c0e5615c3f934e677d5de093a8be7da7ae",
"signature_type": "Line"
}
]