PT-2026-64156 · FFmpeg+3 · Ffmpeg+3
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions 3.4 through 8.1.2
Description
An out-of-bounds write issue exists in the
vf floodfill video filter. This occurs when a dynamically sized video stream is supplied while filtergraph reinitialization is disabled via -reinit filter 0. The config input() function allocates the points traversal stack based on the initial frame dimensions; if a subsequent larger frame is processed, the filter frame() function performs flood-fill neighbor pushes beyond the original allocation boundary. This leads to heap corruption, which can cause a process crash or potentially allow arbitrary code execution depending on the heap layout and process hardening.Recommendations
Update FFmpeg to a version later than 8.1.2.
As a temporary mitigation, avoid using the
vf floodfill filter with the -reinit filter 0 option when processing dynamically sized video streams.Exploit
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ffmpeg
Linuxmint
Red Os
Ubuntu