CVE-2025-9951 is a heap-buffer-overflow write vulnerability in FFmpeg's jpeg2000dec component during processing of JPEG2000 data. The flaw is triggered via the channel definition (cdef) atom in a crafted JPEG2000 file, causing an out-of-bounds write on the heap while decoding malformed input. Successful exploitation may lead to application instability and, depending on memory layout and exploitability conditions, potentially remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file repository contains a standalone Python proof of concept and a Dockerized vulnerable lab for a claimed two-stage vLLM multimodal-media attack chain. exploit.py uses only Python standard-library modules. It first sends invalid image content to an unauthenticated vLLM-compatible API endpoint and extracts a leaked BytesIO object address from the returned Pillow exception. It then builds a malicious JPEG2000/JP2 payload from scratch and delivers it as a data URL or through a temporary attacker-controlled HTTP server. The JP2 cdef box maps a full-resolution component onto a subsampled destination plane, exercising CVE-2025-9951 in FFmpeg 5.1.x through OpenCV VideoCapture. The PoC monitors /health boot_id values to distinguish a target crash/restart from a patched target. It is a crash/memory-corruption PoC, despite the repository's RCE framing: no reliable control-flow hijack or command-execution payload is implemented. lab/app.py is a FastAPI reimplementation of the relevant vLLM ingestion paths, with image loading through Pillow, video loading through cv2.VideoCapture, verbatim exception exposure, /v1/chat/completions and /v1/invocations routes, and a diagnostic /health route. The Docker configuration builds this lab with Python 3.11, FastAPI/Uvicorn, Pillow 11.1.0, and opencv-python-headless 4.11.0.86; docker-compose publishes port 8000 and restarts the container after the expected decoder-induced abort.
Repository contains a local file-based exploitation research PoC for CVE-2025-9951 in FFmpeg’s JPEG 2000/JP2 handling. The core idea is to generate a JP2 file whose codestream geometry and injected CDEF box create a component-to-plane mismatch: a full-resolution component is mapped onto a subsampled chroma plane, producing an out-of-bounds overwrite during decode. The exploit is not remote-ready or portable; it is explicitly constrained to a matching vulnerable FFmpeg research build under a deterministic GDB-launched allocator layout. Structure: README.md explains scope, constraints, and reproduction; WRITEUP.md is a long-form exploitation narrative; generate_poc.py is the main exploit generator; geometry.py is a helper for producing validation-passing JP2 geometry candidates and injecting crafted CDEF metadata; run_poc.gdb launches FFmpeg with allocator-tuning environment variables and feeds poc.jp2 to the decoder. Main exploit capabilities: generate_poc.py reconstructs a 1200-byte desired overwrite region, embeds a benign shell command string, and hardcodes two critical addresses from the documented environment: the destination plane base and libc system(). It then maps desired bytes back into Y-plane source positions so that FFmpeg’s vulnerable decode path writes them into the target memory layout. After creating a temporary YUV file, it invokes opj_compress to build a base JP2, injects/modifies the CDEF box via geometry.inject_cdef(), and writes the final malicious file as poc.jp2. When FFmpeg decodes this file in the documented environment, cleanup reaches the corrupted AVBuffer object and calls system("touch /tmp/cve_2025_9951_small_rce.gdb_proof"). This is a real exploit PoC rather than a detector: it demonstrates code execution, but only with hardcoded addresses and a tightly controlled local setup. Because the payload is fixed and environment-specific rather than user-customizable or framework-driven, the maturity is best classified as OPERATIONAL.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.