Description
A flaw was found in FFmpeg’s ALS audio decoder, where it does not properly check for memory allocation failures. This can cause the application to crash when processing certain malformed audio files. While it does not lead to data theft or system control, it can be used to disrupt services and cause a denial of service.
Problem types
Product status
Any version before 8.0
Timeline
| 2025-07-16: | Reported to Red Hat. |
| 2025-07-15: | Made public. |
Credits
Red Hat would like to thank Jiasheng Jiang for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-7700
bugzilla.redhat.com/show_bug.cgi?id=2380420 (RHBZ#2380420)