PT-2026-76728 · Julia · Ffmpeg Jll+1

Published

2026-08-07

·

Updated

2026-08-07

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read qp offset) while the rv60 qp to idx array has size 64 (valid indices 0-63). This results in out-of-bounds array access at lines 1554 (decode cbp8), 1655 (decode cbp16), and 1419/1421 (get c4x4 set), potentially leading to memory disclosure or crash. A previous fix in commit 61cbcaf93f added validation only for intra frames. This vulnerability affects the released versions 8.0 (released 2025-08-22) and 8.0.1 (released 2025-11-20) and is fixed in git master commit 8abeb879df which will be included in FFmpeg 8.1.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

JLSEC-2026-1170

Affected Products

Ffmpeg Jll
Ffmpeg Nogpl Jll