CVE-2025-22920

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

A heap buffer overflow vulnerability in FFmpeg before commit 4bf784c allows attackers to trigger a memory corruption via supplying a crafted media file in avformat when processing tile grid group streams. This can lead to a Denial of Service (DoS).

Published 2025-02-18. Last modified 2026-06-17.