CVE-2025-1816 - CVE House
Back to Database
Status published Medium CVE-2025-1816

FFmpeg IAMF File iamf_parse.c audio_element_obu memory leak

Vulnerability Description

A vulnerability classified as problematic has been found in FFmpeg up to 6e26f57f672b05e7b8b052007a83aef99dc81ccb. This affects the function audio_element_obu of the file libavformat/iamf_parse.c of the component IAMF File Handler. The manipulation of the argument num_parameters leads to memory leak. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of the patch is 0526535cd58444dd264e810b2f3348b4d96cff3b. It is recommended to apply a patch to fix this issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-1816

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • 0x20z (VulDB User)

Affected Vendor

Affected Software

FFmpeg
Vulnerable Versions:
6e26f57f672b05e7b8b052007a83aef99dc81ccb

Timeline

Official Publish: March 2nd, 2025
Last Modified: March 3rd, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Weaknesses (CWE)