CVE-2025-8586 | libav up to 12.3 MPEG File Parser /libavformat/utils.c ff_seek_frame_binary null pointer dereference (ID 11681 / Nessus ID 253390)
A vulnerability labeled as problematic has been found in libav up to 12.3. Impacted is the function ff_seek_frame_binary of the file /libavformat/utils.c of the component MPEG File Parser. Such manipulation leads to null pointer dereference. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is listed as CVE-2025-8586. The attack must be carried out locally. In addition, an exploit is available.
The bug was initially reported by the researcher to the wrong project.