CVE-2025-6663
AI description
CVE-2025-6663 is a vulnerability in GStreamer, specifically within the parsing of H266 SEI messages. The vulnerability is due to the lack of proper validation of the length of user-supplied data before copying it to a fixed-length stack-based buffer. This flaw can be exploited by remote attackers to execute arbitrary code on systems with affected installations of GStreamer. Exploitation requires interaction with the GStreamer library, though attack vectors could vary depending on the implementation.
- Description
- -
- Hype score
- Not currently trending
CVE-2025-6663 GStreamer H266 Codec Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on af… https://t.co/RcV529LCBc
@CVEnew
7 Jul 2025
177 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
(CVE-2025-6663)[h266parser]Stack-based BoF when parsing subpic_level_inf(parsing of H266 sei messages) -> RCE https://t.co/NaPsD4J5Cm https://t.co/U6jrN4D6vr Reported by Michael Randrianantenaina: https://t.co/k4NRo5Geud https://t.co/V1qoN87SWP
@xvonfers
6 Jul 2025
2074 Impressions
3 Retweets
41 Likes
27 Bookmarks
2 Replies
0 Quotes