CVE-2025-9951
Vulnerability
CVE-2025-9951
CVE-2025-9951
ecosystem: ubuntu:16.04, ubuntu:18.04, ubuntu:20.04, ubuntu:22.04, ubuntu:24.04, ubuntu:25.04A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
References
- launchpad.net/ubuntu-cve-tracker: https://github.com/google/security-research/security/advisories/GHSA-39q3-f8jq-v6mg
- launchpad.net/ubuntu-cve-tracker: https://ubuntu.com/security/notices/USN-7830-1
- launchpad.net/ubuntu-cve-tracker: https://www.cve.org/CVERecord?id=CVE-2025-9951
type: vendor
source: launchpad.net/ubuntu-cve-tracker
published: 2025-09-09 14:15:00
Detection
ubuntu-cve-tracker
OR
 
ffmpeg
package type: source
tag: esm-apps/focal_medium
ubuntu-cve-tracker
OR
 
ffmpeg
package type: source
tag: esm-apps/jammy_medium
OR
 
ffmpeg
package type: source
tag: jammy_medium
ubuntu-cve-tracker
OR
dpkg
ffmpeg
package type: source
Affected version range
less than
7:6.1.1-3ubuntu5+esm6
fixed
7:6.1.1-3ubuntu5+esm6
tag: esm-apps/noble_medium
OR
 
ffmpeg
package type: source
tag: noble_medium
ubuntu-cve-tracker
OR
 
ffmpeg
package type: source
tag: plucky_medium
ubuntu-cve-tracker
OR
 
ffmpeg
package type: source
tag: esm-apps/xenial_medium
ubuntu-cve-tracker
OR
 
ffmpeg
package type: source
tag: esm-apps/bionic_medium
Data Sources
- Ubuntu CVE Tracker
ubuntu-cve-tracker