Bug 2401840 - CVE-2025-59734 ffmpeg: Heap-buffer-overflow write in FFmpeg SANM process_ftch [epel-9]
Summary: CVE-2025-59734 ffmpeg: Heap-buffer-overflow write in FFmpeg SANM process_ftch...
Keywords:
Status: NEW
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: ffmpeg
Version: epel9
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Multimedia SIG
QA Contact:
URL:
Whiteboard: {"flaws": ["bbad36ce-ece6-4dc1-9882-4...
Depends On:
Blocks: CVE-2025-59734
TreeView+ depends on / blocked
 
Reported: 2025-10-06 10:43 UTC by Sandipan Roy
Modified: 2026-05-22 11:53 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Sandipan Roy 2025-10-06 10:43:47 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams

Comment 1 Dominik 'Rathann' Mierzejewski 2026-05-22 11:53:28 UTC
A.k.a BIGSLEEP-440183164
Fixed in 8.1: https://github.com/FFmpeg/FFmpeg/commit/c41a70b6bb79707e1e3a4b0e31950cd986b9f50e
fix not backported to older releases, so EPEL9 is affected.


Note You need to log in before you can comment on or make changes to this bug.