PT-2026-64154 · FFmpeg · Ffmpeg

·

CVE-2026-65703

·

Publicado

2026-07-23

·

Atualizado

2026-07-23

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc parse tdsf() function fails to unreference the existing reference frame before calling av frame get buffer(), causing tdsc blit() and tdsc yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution.

Correção

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-65703

Produtos afetados

Ffmpeg