{"id":2989,"date":"2025-11-13T18:53:05","date_gmt":"2025-11-14T01:53:05","guid":{"rendered":"https:\/\/catbradley.io\/?p=2989"},"modified":"2025-11-13T18:53:05","modified_gmt":"2025-11-14T01:53:05","slug":"ffmpeg-calls-googles-ai-bug-reports-cve-slop","status":"publish","type":"post","link":"https:\/\/catbradley.io\/?p=2989","title":{"rendered":"FFmpeg Calls Google&#8217;s AI Bug Reports &#8220;CVE Slop&#8221;"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/itsfoss.com\/content\/images\/2025\/11\/ffmpeg-unhappy-with-google.png\" alt=\"FFmpeg Calls Google's AI Bug Reports &quot;CVE Slop&quot;\" \/><\/p>\n<p><a href=\"https:\/\/www.ffmpeg.org\/?ref=itsfoss.com\">FFmpeg<\/a> maintainers have publicly criticized Google after its AI tool reported a security bug in code for a 1995 video game.<\/p>\n<p>The maintainers called the finding &#8220;<a href=\"https:\/\/x.com\/ffmpeg\/status\/1984207514389586050?ref=itsfoss.com\" rel=\"noreferrer\">CVE slop<\/a>&#8221; and questioned whether trillion-dollar corporations should use AI to find security issues in volunteer code without providing fixes.<\/p>\n<h2>Unchecked Automation is Not an Answer<\/h2>\n<figure class=\"kg-card kg-embed-card\">\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Patch to fix an issue with decoding LucasArts Smush codec, specifically the first 10-20 frames of Rebel Assault 2, a game from 1995.<\/p>\n<p>FFmpeg aims to play every video file ever made. <a href=\"https:\/\/t.co\/9WryDgDpER?ref=itsfoss.com\">pic.twitter.com\/9WryDgDpER<\/a><\/p>\n<p>\u2014 FFmpeg (@FFmpeg) <a href=\"https:\/\/twitter.com\/FFmpeg\/status\/1983949866725437791?ref_src=twsrc%5Etfw&amp;ref=itsfoss.com\">October 30, 2025<\/a><\/p><\/blockquote>\n<\/figure>\n<p><strong>So what happened is<\/strong>, Google&#8217;s AI agent Big Sleep found <a href=\"https:\/\/x.com\/FFmpeg\/status\/1983949866725437791?ref=itsfoss.com\">a bug<\/a> in FFmpeg&#8217;s code for decoding LucasArts Smush codec. The issue affected the first 10-20 frames of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Star_Wars:_Rebel_Assault_II:_The_Hidden_Empire?ref=itsfoss.com\" rel=\"noreferrer\">Rebel Assault II<\/a>, a game from 1995.<\/p>\n<p>If you didn&#8217;t know, <a href=\"https:\/\/googleprojectzero.blogspot.com\/2024\/10\/from-naptime-to-big-sleep.html?ref=itsfoss.com\">Big Sleep<\/a> is Google&#8217;s AI-powered vulnerability detection tool developed by its Project Zero and DeepMind divisions. It is supposed to find security vulnerabilities in software before attackers can exploit them.<\/p>\n<p>But there&#8217;s an issue here: under Google&#8217;s &#8220;<a href=\"https:\/\/googleprojectzero.blogspot.com\/2025\/07\/reporting-transparency.html?ref=itsfoss.com\">Reporting Transparency<\/a>&#8221; policy, the tech giant publicly announces it has found a vulnerability within one week of reporting it. A 90-day disclosure clock then starts regardless of whether a patch is available.<\/p>\n<p><em>You see the problem now? <\/em>\ud83e\udd14<\/p>\n<p>FFmpeg developers patched the bug but weren&#8217;t happy about it. They tweeted in <a href=\"https:\/\/x.com\/FFmpeg\/status\/1984178359354483058?ref=itsfoss.com\">late October<\/a> that &#8220;<em>We take security very seriously but at the same time is it really fair that trillion-dollar corporations run AI to find security issues in people&#8217;s hobby code? Then expect volunteers to fix<\/em>.&#8221;<\/p>\n<p>Beyond that, you have to understand that<strong> FFmpeg is an important piece of digital infrastructure<\/strong> that is used in Google Chrome, Firefox, YouTube, VLC, Kodi, and many other platforms.<\/p>\n<p>The project is written almost exclusively by volunteers. Much of the code is in <a href=\"https:\/\/en.wikipedia.org\/wiki\/Assembly_language?ref=itsfoss.com\">assembly language<\/a>, which is difficult to work with. This situation basically highlights <a href=\"https:\/\/itsfoss.com\/news\/open-source-infrastructure-is-breaking-down\/\">the ongoing tensions<\/a> over how corporations use volunteer-maintained open source software that powers their commercial products and expect them to fix any obscure issues that crop up.<\/p>\n<p>Via: <a href=\"https:\/\/thenewstack.io\/ffmpeg-to-google-fund-us-or-stop-sending-bugs\/?ref=itsfoss.com\">The New Stack<\/a><\/p>\n<p><strong>Suggested Reads \ud83d\udcd6<\/strong><\/p>\n<figure class=\"kg-card kg-bookmark-card\"><a class=\"kg-bookmark-container\" href=\"https:\/\/itsfoss.com\/news\/open-source-infrastructure-is-breaking-down\/\">\n<div class=\"kg-bookmark-content\">\n<div class=\"kg-bookmark-title\">Open Source Infrastructure is Breaking Down Due to Corporate Freeloading<\/div>\n<div class=\"kg-bookmark-description\">An unprecedented threat looms over open source.<\/div>\n<div class=\"kg-bookmark-metadata\"><img decoding=\"async\" class=\"kg-bookmark-icon\" src=\"https:\/\/itsfoss.com\/content\/images\/icon\/android-chrome-512x512-20.png\" alt=\"FFmpeg Calls Google's AI Bug Reports &quot;CVE Slop&quot;\" \/><span class=\"kg-bookmark-author\">It&#8217;s FOSS<\/span><span class=\"kg-bookmark-publisher\">Sourav Rudra<\/span><\/div>\n<\/div>\n<div class=\"kg-bookmark-thumbnail\"><img decoding=\"async\" src=\"https:\/\/itsfoss.com\/content\/images\/thumbnail\/openssf-letter-to-big-corporations-2.png\" alt=\"FFmpeg Calls Google's AI Bug Reports &quot;CVE Slop&quot;\" \/><\/div>\n<p><\/p><\/a><\/figure>\n<figure class=\"kg-card kg-bookmark-card\"><a class=\"kg-bookmark-container\" href=\"https:\/\/itsfoss.com\/news\/ffmpeg-receives-100k-funding\/\">\n<div class=\"kg-bookmark-content\">\n<div class=\"kg-bookmark-title\">FFmpeg Receives $100K in Funding from India\u2019s FLOSS\/fund Initiative<\/div>\n<div class=\"kg-bookmark-description\">It is one of the world\u2019s most widely used multimedia frameworks today.<\/div>\n<div class=\"kg-bookmark-metadata\"><img decoding=\"async\" class=\"kg-bookmark-icon\" src=\"https:\/\/itsfoss.com\/content\/images\/icon\/android-chrome-512x512-19.png\" alt=\"FFmpeg Calls Google's AI Bug Reports &quot;CVE Slop&quot;\" \/><span class=\"kg-bookmark-author\">It&#8217;s FOSS<\/span><span class=\"kg-bookmark-publisher\">Sourav Rudra<\/span><\/div>\n<\/div>\n<div class=\"kg-bookmark-thumbnail\"><img decoding=\"async\" src=\"https:\/\/itsfoss.com\/content\/images\/thumbnail\/ffmpeg-funding-floss-fund.png\" alt=\"FFmpeg Calls Google's AI Bug Reports &quot;CVE Slop&quot;\" \/><\/div>\n<p><\/p><\/a><\/figure>","protected":false},"excerpt":{"rendered":"<p>FFmpeg maintainers have publicly criticized Google after its AI tool reported a security bug in code for a 1995 video game. The maintainers called the finding &#8220;CVE slop&#8221; and questioned&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-2989","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-rss"],"_links":{"self":[{"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/posts\/2989","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/catbradley.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2989"}],"version-history":[{"count":0,"href":"https:\/\/catbradley.io\/index.php?rest_route=\/wp\/v2\/posts\/2989\/revisions"}],"wp:attachment":[{"href":"https:\/\/catbradley.io\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2989"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/catbradley.io\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2989"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/catbradley.io\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2989"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}