PT-2026-78524 · FFmpeg+2 · Ffmpeg+2
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to commit acf5d7c
Description
A heap buffer overflow exists in the hvcC box writer. This occurs when writing an HEVC configuration record containing more NAL units of a single type than the count field can represent, leading to a NAL unit count overflow. A specially crafted HEVC input file can trigger this overflow during the muxing process.
Recommendations
Update FFmpeg to the version containing commit acf5d7c or later.
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ffmpeg
Linuxmint
Ubuntu