PT-2026-64157 · FFmpeg+3 · Ffmpeg+3
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions 3.0 through 8.1.2
Description
An out-of-bounds write exists in the
vf swaprect video filter. This occurs when the filter frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes. When processing a crafted NV12 video frame with odd width dimensions, such as a 17x16 frame, an 18-byte memcpy is performed into a 17-byte heap allocation for the interleaved chroma plane. This leads to heap corruption, which can cause the process to crash or potentially allow for arbitrary code execution.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ffmpeg
Linuxmint
Red Os
Ubuntu