PT-2026-53081 · FFmpeg+1 · Ffmpeg+1
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to the latest patch
Description
The RASC video decoder in libavcodec contains a flaw where the
decode dlta() function in libavcodec/rasc.c performs 32-bit reads and writes at the row cursor before the NEXT LINE row-boundary check. Additionally, the DLTA region is validated in pixel units instead of byte units. This allows a DLTA run on a PAL8 frame to access bytes beyond the row allocation. A specially crafted media stream using the RASC FourCC can trigger a bitstream-controlled out-of-bounds heap write and an adjacent out-of-bounds read, resulting in memory corruption, denial of service, or potential arbitrary code execution.Recommendations
Update to the latest version.
Exploit
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ffmpeg
Red Os