PT-2026-78526 · FFmpeg+2 · Ffmpeg+2
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FFmpeg versions prior to commit 1c10bcc
Description
A heap buffer overflow exists in the RIST protocol reader within
libavformat/librist.c. The function librist read() fails to respect its size argument, copying the entire received payload length into the destination buffer. This leads to an overflow when the payload size exceeds the buffer capacity. The issue is accessible via the async:rist:// URL scheme, where the async wrapper provides a buffer smaller than the incoming payload. A remote RIST sender can trigger this condition by sending a packet with a payload that exceeds the caller buffer size.Recommendations
Update FFmpeg to the version containing commit 1c10bcc or later.
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ffmpeg
Linuxmint
Ubuntu