PT-2026-64412 · FFmpeg+3 · Ffmpeg+3
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to 8.1.2
Description
A heap out-of-bounds write exists in the
vf hqdn3d filter. This occurs when filtergraph reinitialization is disabled using the -reinit filter 0 option. An attacker can provide a crafted video where the frame resolution increases between frames. In this scenario, the config input() function allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause the denoise spatial() function to write beyond the allocated boundary, leading to heap memory corruption.Recommendations
Update to the version containing commit 5d7112c.
Avoid using the
-reinit filter 0 option when processing untrusted video inputs.Exploit
Fix
DoS
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ffmpeg
Linuxmint
Red Os
Ubuntu