PT-2026-64155 · FFmpeg+3 · Ffmpeg+3
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to 8.1.3
Description
An out-of-bounds write issue exists when processing a crafted ffconcat file using the
-safe 0 flag. The demux audio() function within the TY demuxer decrements the packet size without performing bounds checking. This results in a negative size value being passed to the memcpy() function inside shorten decode frame(). The subsequent conversion to size t causes the value to wrap to near SIZE MAX, leading to reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer, which causes heap corruption.Recommendations
Update to a version newer than 8.1.2.
Avoid using the
-safe 0 flag when processing ffconcat files.Exploit
Fix
DoS
Memory Corruption
Integer Underflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ffmpeg
Linuxmint
Red Os
Ubuntu