PT-2026-78527 · FFmpeg+2 · Ffmpeg+2

·

CVE-2026-75144

·

Published

2026-08-19

·

Updated

2026-09-09

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to commit 1cdeb3c
Description A heap buffer overflow exists in the VC-2/Dirac RTP packetizer within the libavformat/rtpenc vc2hq.c file. The issue occurs because the packetizer copies an input-derived data unit or fragment size into a fixed-size buffer without performing an upper bound check. An attacker can trigger memory corruption by supplying a specially crafted Dirac data unit during the process of packetizing input for RTP output.
Recommendations Update FFmpeg to the version containing commit 1cdeb3c or later.

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75144
ECHO-D43D-3438-B69F
OESA-2026-3541
OESA-2026-3542
OESA-2026-3543
OESA-2026-3544
OESA-2026-3545
OPENSUSE-SU-2026:11659-1
OPENSUSE-SU-2026:11665-1
OPENSUSE-SU-2026:11682-1
OPENSUSE-SU-2026:11716-1
USN-8716-1
USN-8716-2

Affected Products

Ffmpeg
Linuxmint
Ubuntu