SUSE ffmpeg-4 Security Fixes Address Multiple Vulnerabilities

SUSE ffmpeg-4 Security Fixes Address Multiple Vulnerabilities

First seen 18 Jun 2026, 22:24 UTC Linuxsecurity 98% similarity 57.9

Article Content

Browse articles
ThreatCluster

SUSE released an important update for ffmpeg-4 on June 18, 2026, addressing several vulnerabilities. The update includes fixes for CVE-2023-6601, CVE-2024-35366, CVE-2025-1594, CVE-2025-9951, CVE-2025-10256, and CVE-2025-63757. These vulnerabilities include issues such as an HLS Unsafe File Extension Bypass and multiple buffer overflows that could lead to denial of service. The vulnerabilities affect the ffmpeg-4 software, which is widely used for multimedia processing. Security ratings for these vulnerabilities range from 3.3 to 6.9 on the CVSS scale, indicating varying levels of severity. Users are urged to apply the updates promptly to mitigate potential risks. The vulnerabilities were identified in various components of ffmpeg, including libavformat and libavcodec. This update is crucial for maintaining the security of systems utilizing ffmpeg.

Key Points: • SUSE released an important update for ffmpeg-4 on June 18, 2026. • The update addresses multiple vulnerabilities, including buffer overflows and unsafe file extension bypass. • Affected CVEs include CVE-2023-6601, CVE-2024-35366, and CVE-2025-1594.

ThreatCluster AI How this analysis works

Timeline

2024-11-29
CVE-2024-35366 published
Integer Overflow vulnerability identified in ffmpeg's parse_options function.
Linuxsecurity
2025-01-06
CVE-2023-6601 published
HLS Unsafe File Extension Bypass vulnerability disclosed, affecting ffmpeg-4.
Linuxsecurity
2025-02-23
CVE-2025-1594 published
Stack-based buffer overflow in AAC Encoder function reported in ffmpeg.
Linuxsecurity
2025-09-09
CVE-2025-9951 published
Heap-based buffer overflow vulnerability in jpeg2000dec disclosed for ffmpeg.
Linuxsecurity
2025-12-18
CVE-2025-63757 published
Accumulation of filtered pixel values leading to an integer overflow vulnerability disclosed.
Linuxsecurity
2026-02-18
CVE-2025-10256 published
NULL pointer dereference vulnerability in Firequalizer filter reported for ffmpeg.
Linuxsecurity
2026-06-18
SUSE ffmpeg-4 update released
SUSE released an important update for ffmpeg-4 addressing multiple vulnerabilities.
Linuxsecurity

Community

Browse all →