PT-2026-50871 · FFmpeg · Ffmpeg

·

CVE-2026-12706

·

Published

2026-06-19

·

Updated

2026-08-15

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg (affected versions not specified)
Description A use-after-free issue exists in the RASC video decoder. The decode move() function initializes a read pointer into a decompressed buffer; however, a subsequent reallocation of that buffer during move-table processing results in a dangling pointer. An attacker can trigger this by providing a specially crafted AVI file containing a malicious RASC video stream, causing the decoder to read from freed heap memory, which may lead to a denial of service (crash).
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12706
OESA-2026-2826
OESA-2026-2827
OESA-2026-2828
OESA-2026-2829
OPENSUSE-SU-2026:11347-1
OPENSUSE-SU-2026:11360-1
OPENSUSE-SU-2026:11361-1
OPENSUSE-SU-2026:11515-1
SUSE-SU-2026:3529-1
SUSE-SU-2026:3542-1

Affected Products

Ffmpeg