CVE-2025-54957CRITICAL 9.8EPSS p72.8%

CVE-2025-54957CVE-2025-54957

Description

An issue was discovered in Dolby UDC 4.5 through 4.13. A crash of the DD+ decoder process can occur when a malformed DD+ bitstream is processed. When Evolution data is processed by evo_priv.c from the DD+ bitstream, the decoder writes that data into a buffer. The length calculation for a write can overflow due to an integer wraparound. This can lead to the allocated buffer being too small, and the out-of-bounds check of the subsequent write to be ineffective, leading to an out-of-bounds write.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS1.61% probability of exploitation · percentile 72.8% · 2026-06-18T12:00:27Z
Published2025-10-20
Last modified2026-04-15

Underlying weaknesses· 2

CWE-190CWE-787

References

  1. https://professional.dolby.com/siteassets/pdfs/dolby-security-advisory-CVE-2025-54957-Oct-14-25.pdf
  2. https://project-zero.issues.chromium.org/issues/428075495
  3. https://projectzero.google/2026/01/pixel-0-click-part-1.html

2

TypeTargetConfidenceTier
WeaknessInteger Overflow or Wraparoundcwe-1900%live
WeaknessOut-of-bounds Writecwe-7870%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2025-55659
CVE
CVE-2025-55657
CVE
CVE-2025-55651
CVE
CVE-2025-60485
CVE
CVE-2025-48174
CVE
CVE-2025-59605
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.