PT-2022-7212 · FFmpeg+2 · Ffmpeg+2

·

CVE-2022-3965

·

Published

2022-11-12

·

Updated

2026-02-06

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg (affected versions not specified)
Description The issue is related to the smc encode stream function in the libavcodec/smcenc.c component of the FFmpeg library. It involves an out-of-bounds read due to the manipulation of the y size argument, which can be exploited remotely. This could allow an attacker to access confidential data and cause a denial of service.
Recommendations To fix this issue, it is recommended to apply a patch. The specific patch name is 13c13109759090b7f7182480d075e13b36ed8edd. As a temporary workaround, consider restricting access to the smc encode stream function until a patch is available. Additionally, avoid manipulating the y size argument in the affected component to minimize the risk of exploitation.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-09096
CLEANSTART-2026-EZ98723
CLEANSTART-2026-PS82605
CLEANSTART-2026-XE32069
CVE-2022-3965
USN-5958-1

Affected Products

Ffmpeg
Linuxmint
Ubuntu