CVE-2025-22920

Source
https://cve.org/CVERecord?id=CVE-2025-22920
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22920.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-22920
Downstream
Related
Published
2025-02-18T00:00:00Z
Modified
2026-08-17T04:12:29.796142Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/22xxx/CVE-2025-22920.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / git.ffmpeg.org/ffmpeg.git

Affected ranges

Type
GIT
Repo
https://git.ffmpeg.org/ffmpeg.git
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Other
N
n0.*
n0.11-dev
n0.12-dev
n0.8
n1.*
n1.1-dev
n1.2-dev
n1.3-dev
n2.*
n2.0
n2.1-dev
n2.2-dev
n2.3-dev
n2.4-dev
n2.5-dev
n2.6-dev
n2.7-dev
n2.8-dev
n2.9-dev
n3.*
n3.1-dev
n3.2-dev
n3.3-dev
n3.4-dev
n3.5-dev
n4.*
n4.1-dev
n4.2-dev
n4.3-dev
n4.4-dev
n4.5-dev
n5.*
n5.1-dev
n5.2-dev
n6.*
n6.1-dev
n6.2-dev
n7.*
n7.1-dev
n7.2-dev

Database specific

vanir_signatures_modified
"2026-08-17T04:12:29Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-22920.json"
vanir_signatures
[
    {
        "deprecated": false,
        "target": {
            "file": "libavformat/dump.c",
            "function": "dump_stream_group"
        },
        "id": "CVE-2025-22920-032c8ef3",
        "signature_version": "v1",
        "digest": {
            "function_hash": "70396055671749122657989014028539752311",
            "length": 5658.0
        },
        "source": "https://git.ffmpeg.org/ffmpeg.git@4bf784c0e5615c3f934e677d5de093a8be7da7ae",
        "signature_type": "Function"
    },
    {
        "deprecated": false,
        "target": {
            "file": "libavformat/dump.c"
        },
        "id": "CVE-2025-22920-2feb5b98",
        "signature_version": "v1",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "312459793511290586234133337784754532888",
                "183607684213541125376994226150133169831",
                "30403947470803405872314873576994182819",
                "101234647407442325980436209429316218007",
                "241933069208255574297658600788560652581"
            ]
        },
        "source": "https://git.ffmpeg.org/ffmpeg.git@4bf784c0e5615c3f934e677d5de093a8be7da7ae",
        "signature_type": "Line"
    }
]