/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CGA-p36g-4pj5-68wh

Published

Last updated

https://images.chainguard.dev/security/CGA-p36g-4pj5-68wh
Package

ffmpeg-6

Repository

Chainguard

Latest Update
Pending upstream fix
Aliases
  • CVE-2025-22919
  • GHSA-hcqg-278r-c3pp

Severity

Unknown

References

  • https://nvd.nist.gov/vuln/detail/CVE-2025-22919

Updates

Status

Pending upstream fix

Impact

The buffersrc null pointer dereference vulnerability is NOT fixed in FFmpeg 6.1.2. While FFmpeg 6.1.2 does have null checks in buffersrc.c, this specific CVE from 2025 identifies a new vulnerability path that wasn't addressed in the 2017 fixes. Since FFmpeg 6.x branch last released in 2024, this 2025 CVE cannot be fixed in the current 6.1.2 version. The fix needs to be backported from newer FFmpeg versions.

Status

Under investigation


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing