A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.

Project Subscriptions

Vendors Products
Advisories
Source ID Title
Debian DLA Debian DLA DLA-4440-1 ffmpeg security update
Debian DSA Debian DSA DSA-6007-1 ffmpeg security update
Fixes

Solution

No solution given by the vendor.


Workaround

No mitigation is currently available that meets Red Hat Product Security's standards for usability, deployment, applicability, or stability.

History

Fri, 27 Feb 2026 05:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 26 Feb 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Ffmpeg
Ffmpeg ffmpeg
CPEs cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Vendors & Products Ffmpeg
Ffmpeg ffmpeg

Wed, 18 Feb 2026 20:45:00 +0000

Type Values Removed Values Added
Description A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.
Title Ffmpeg: null pointer dereference in firequalizer filter (libavfilter/af_firequalizer.c)
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-02-25T16:55:10.204Z

Reserved: 2025-09-11T06:11:12.091Z

Link: CVE-2025-10256

cve-icon Vulnrichment

Updated: 2026-02-25T16:55:03.520Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-18T21:16:20.183

Modified: 2026-02-26T22:33:18.823

Link: CVE-2025-10256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses