PT-2025-40874 · Mpeg-Dash+4 · Mpeg-Dash+4

CVE-2025-59728

·

Published

2025-07-22

·

Updated

2026-06-18

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Software versions prior to 8.0
Description An issue exists in the handling of MPEG-DASH manifests where an out-of-bounds NUL-byte write occurs one byte past the end of the buffer. This happens during the calculation of the content path. The xmlNodeGetContent function returns a buffer allocated to match the string length using strdup. If the buffer is not empty, it is assigned to root url. If the last byte in the buffer is not '/', a '/' is appended, potentially writing beyond the buffer's allocated space.
Recommendations Upgrade to version 8.0 or beyond.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-12716
CVE-2025-59728
MGASA-2025-0306
OESA-2026-2662
OESA-2026-2663
OESA-2026-2664
OESA-2026-2665
OPENSUSE-SU-2025:15640-1
OPENSUSE-SU-2026:20710-1
OPENSUSE-SU-2026:20855-1
SUSE-SU-2025:3715-1
SUSE-SU-2025:3810-1
SUSE-SU-2025_3810-1
SUSE-SU-2026:2444-1
SUSE-SU-2026:2445-1
USN-7982-1

Affected Products

Linuxmint
Mpeg-Dash
Red Os
Suse
Ubuntu