DEBIAN-CVE-2025-14569

Source
https://security-tracker.debian.org/tracker/CVE-2025-14569
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-14569.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2025-14569
Upstream
Published
2025-12-12T19:16:01.610Z
Modified
2026-06-11T09:03:29.819645592Z
Summary
[none]
Details

A vulnerability was detected in ggml-org whisper.cpp up to 1.8.2. Affected is the function readaudiodata of the file /whisper.cpp/examples/common-whisper.cpp. The manipulation results in use after free. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References

Affected packages

Debian:14 / whisper.cpp

Package

Name
whisper.cpp
Purl
pkg:deb/debian/whisper.cpp?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.7.6+dfsg-1
1.8.2+dfsg-1
1.8.2+dfsg-2
1.8.2+dfsg-3
1.8.2+dfsg-4
1.8.2+dfsg-5
1.8.3+dfsg-1
1.8.3+dfsg-2~exp1
1.8.3+dfsg-2~exp2
1.8.3+dfsg-2
1.8.4+dfsg-1
1.8.6+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-14569.json"