CVE-2025-9951
Publication date 9 September 2025
Last updated 21 October 2025
Ubuntu priority
Description
A heap-buffer-overflow write exists in jpeg2000dec FFmpeg which allows an attacker to potentially gain remote code execution or cause denial of service via the channel definition cdef atom of JPEG2000.
Status
Package | Ubuntu Release | Status |
---|---|---|
ffmpeg | 25.10 questing |
Vulnerable
|
25.04 plucky |
Vulnerable
|
|
24.04 LTS noble |
Fixed 7:6.1.1-3ubuntu5+esm6
|
|
22.04 LTS jammy |
Vulnerable
|
|
20.04 LTS focal | Ignored backport too intrusive | |
18.04 LTS bionic | Ignored backport too intrusive | |
16.04 LTS xenial |
Vulnerable
|
|
libav | 25.10 questing | Not in release |
25.04 plucky | Not in release | |
24.04 LTS noble | Not in release | |
22.04 LTS jammy | Not in release | |
14.04 LTS trusty |
Needs evaluation
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu Pro 30-day free trialReferences
Related Ubuntu Security Notices (USN)
- USN-7830-1
- FFmpeg vulnerabilities
- 21 October 2025