CVE-2025-54957 Details
Description
An issue was discovered in Dolby UDC 4.5 through 4.13. A crash of the DD+ decoder process can occur when a malformed DD+ bitstream is processed. When Evolution data is processed by evo_priv.c from the DD+ bitstream, the decoder writes that data into a buffer. The length calculation for a write can overflow due to an integer wraparound. This can lead to the allocated buffer being too small, and the out-of-bounds check of the subsequent write to be ineffective, leading to an out-of-bounds write.
A vulnerability allowing out-of-bounds write has been identified in Dolby UDC versions 4.5 through 4.13. This issue arises when the DD+ decoder processes a malformed, manually edited bitstream, leading to a crash of the decoder process. The problem occurs in the 'evo_priv.c' component, where the length calculation for writing data can overflow, causing the allocated buffer to be too small. This buffer overflow allows for an out-of-bounds write, as the subsequent write's out-of-bounds check becomes ineffective.
Dolby advises OEMs and component providers with products that incorporate DD+ to contact their Dolby representative for the latest Dolby Digital Plus deliverables. Consumers should keep their devices up to date and enable automatic updates when supported. For specific device inquiries, consumers should reach out to the original device manufacturer.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 20, 2025CISA-ADP
Assessed Jan 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
Affected Products
| Product | Versions |
|---|---|
| Dolby UDC | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 15, 2026 | CVE Modified | CISA-ADP |
| Jan 6, 2026 | CVE Modified | CISA-ADP |
| Oct 20, 2025 | CVE Modified | CISA-ADP |
| Oct 20, 2025 | New CVE Received | [email protected] |
Volerion