← back
CVE-2025-26305highCWE-244

CVE-2025-26305

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.2epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
In short

A memory leak in libming's SWF file parser allows attackers to crash applications by sending specially crafted SWF files. This vulnerability can disrupt services that process SWF files without proper resource management.

Technical detail

The parseSWF_SOUNDINFO function in util/parser.c fails to properly release allocated memory when processing SWF SOUNDINFO structures, enabling a denial of service attack vector. An attacker can trigger memory exhaustion by submitting multiple or specially crafted SWF files, resulting in process termination or service unavailability.

Summary generated and translated by AI from the official description.
A memory leak has been identified in the parseSWF_SOUNDINFO function in util/parser.c of libming v0.4.8, which allows attackers to cause a denial of service via a crafted SWF file.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Affected products
n/a · n/a