PT-2026-78524 · FFmpeg+2 · Ffmpeg+2

·

CVE-2026-75141

·

Published

2026-08-19

·

Updated

2026-09-09

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to commit acf5d7c
Description A heap buffer overflow exists in the hvcC box writer. This occurs when writing an HEVC configuration record containing more NAL units of a single type than the count field can represent, leading to a NAL unit count overflow. A specially crafted HEVC input file can trigger this overflow during the muxing process.
Recommendations Update FFmpeg to the version containing commit acf5d7c or later.

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75141
ECHO-EF47-70D2-ABED
OESA-2026-3541
OESA-2026-3542
OESA-2026-3543
OESA-2026-3544
OESA-2026-3545
OPENSUSE-SU-2026:11659-1
OPENSUSE-SU-2026:11665-1
OPENSUSE-SU-2026:11682-1
USN-8716-1
USN-8716-2

Affected Products

Ffmpeg
Linuxmint
Ubuntu