CVE-2025-71264

NameCVE-2025-71264
DescriptionMumble before 1.6.870 is prone to an out-of-bounds array access, which ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1129178

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
mumble (PTS)bullseye1.3.4-1vulnerable
bookworm1.3.4-4vulnerable
trixie1.5.735-5vulnerable
forky, sid1.5.735-8fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
mumblesource(unstable)1.5.735-71129178

Notes

[trixie] - mumble <no-dsa> (Minor issue; will be fixed via point release)
[bookworm] - mumble <no-dsa> (Minor issue; will be fixed via point release)
[bullseye] - mumble <postponed> (Minor issue)
https://github.com/mumble-voip/mumble/pull/7032
Fixed by (merge): https://github.com/mumble-voip/mumble/commit/ff2a2332cccb267721553f09c0ded4de880622e0

Search for package or bug name: Reporting problems