UBUNTU-CVE-2025-14569

Source
https://ubuntu.com/security/CVE-2025-14569
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-14569.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2025-14569
Upstream
Published
2025-12-12T19:16:00Z
Modified
2026-05-20T16:20:22.957766385Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A vulnerability was detected in ggml-org whisper.cpp up to 1.8.2. Affected is the function readaudiodata of the file /whisper.cpp/examples/common-whisper.cpp. The manipulation results in use after free. The attack requires a local approach. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

References

Affected packages

Ubuntu:26.04:LTS / whisper.cpp

Package

Name
whisper.cpp
Purl
pkg:deb/ubuntu/whisper.cpp?arch=source&distro=resolute

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.8.3+dfsg-2

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "libwhisper1",
            "binary_version": "1.8.3+dfsg-2"
        },
        {
            "binary_name": "whisper.cpp",
            "binary_version": "1.8.3+dfsg-2"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-14569.json"