CVE-2026-70629
Description
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords4 versionspkg:rpm/opensuse/ffmpeg-4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-8&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-9&distro=openSUSE%20Tumbleweed
< 4.4.8-5.1+ 3 more
- (no CPE)range: < 4.4.8-5.1
- (no CPE)range: < 7.1.5-2.1
- (no CPE)range: < 8.1.2-3.1
- (no CPE)range: < 9.0.1-3.1
Patches
Vulnerability mechanics
References
5- code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85accnvdPatch
- code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4nvdPatch
- code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7nvdPatch
- code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895nvdIssue TrackingPatch
- www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decodernvdPatchThird Party Advisory
News mentions
1- FFmpeg: Five Vulnerabilities Disclosed, Two High Severity Heap Corruption FlawsVypr Intelligence · Aug 6, 2026