PT-2021-5754 · FFmpeg+5 · Ffmpeg+5

Maryam Ebrahimzadeh

·

Published

2021-08-06

·

Updated

2026-02-06

·

CVE-2021-38171

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg version 4.4
Description The issue is related to the adts decode extradata function in the libavformat/adtsenc.c component of the FFmpeg library. It does not check the return value of init get bits, which can be crafted by an attacker. This could allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service.
Recommendations For FFmpeg version 4.4, consider disabling the adts decode extradata function until a patch is available. Restrict access to the libavformat/adtsenc.c module to minimize the risk of exploitation. Avoid using the init get bits function with crafted second arguments in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unchecked Return Value

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2900
ALT-PU-2021-2999
ALT-PU-2021-3166
ALT-PU-2021-3508
ALT-PU-2021-3575
ALT-PU-2022-1821
BDU:2022-00199
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2021-38171
DLA-2818-1
DSA-4990-1
DSA-4998-1
MGASA-2021-0495
OESA-2024-1804
OESA-2024-1806
OESA-2024-1807
OESA-2024-1808
OPENSUSE-SU-2021:3193-1
OPENSUSE-SU-2021_3193-1
OPENSUSE-SU-2024:10754-1
SUSE-SU-2021:3193-1
SUSE-SU-2021:3212-1
SUSE-SU-2021_3193-1
SUSE-SU-2021_3212-1
USN-5167-1
USN-5472-1

Affected Products

Alt Linux
Astra Linux
Ffmpeg
Linuxmint
Suse
Ubuntu