A vulnerability labeled as critical has been found in FFmpeg up to 7.x. Affected is the function
uncompressed_data
of the component OpenEXR File Decoder. Such manipulation leads to out-of-bounds write.
This vulnerability is referenced as CVE-2025-59732. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.