Out-of-Bounds Read in FFmpeg Video Decoder by FFmpeg
CVE-2025-69693
5.4MEDIUM
What is CVE-2025-69693?
An out-of-bounds read vulnerability exists in FFmpeg 8.0 and 8.0.1, specifically in the RV60 video decoder. The lack of an upper boundary check on the quantization parameter (qp) exposes the decoder to potential memory disclosure or crashes. As the qp value can exceed the valid range defined in the rv60_qp_to_idx array, this flaw could be exploited during the decoding process. This issue, present in several lines of the code, remains a risk despite prior fixes that only addressed intra frame validations. The vulnerability has been remedied in the upcoming FFmpeg version 8.1.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
