CVE-2025-25467

NameCVE-2025-25467
DescriptionInsufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
x264 (PTS)bullseye2:0.160.3011+gitcde9a93-2.1vulnerable
bookworm2:0.164.3095+gitbaee400-3vulnerable
sid, trixie2:0.164.3108+git31e19f9-2vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
x264source(unstable)(unfixed)

Notes

https://code.videolan.org/videolan/x264/-/issues/75

Search for package or bug name: Reporting problems