GHSA-72cw-2m7j-25c8HighCVSS 7.8
FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing...
🔗 CVE IDs covered (1)
📋 Description
FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-75141
- https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781
- https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24088
- https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-in-hvcc-box-writer-via-hevc-muxing
- https://github.com/advisories/GHSA-72cw-2m7j-25c8