ffmpeg-6
Chainguard
Status
Impact
The buffersrc null pointer dereference vulnerability is NOT fixed in FFmpeg 6.1.2. While FFmpeg 6.1.2 does have null checks in buffersrc.c, this specific CVE from 2025 identifies a new vulnerability path that wasn't addressed in the 2017 fixes. Since FFmpeg 6.x branch last released in 2024, this 2025 CVE cannot be fixed in the current 6.1.2 version. The fix needs to be backported from newer FFmpeg versions.
Status