rpm package
opensuse/ffmpeg-8&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/ffmpeg-8&distro=openSUSE%20Tumbleweed
Vulnerabilities (35)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-18393 | Med | 5.4 | < 8.1.2-5.1 | 8.1.2-5.1 | Aug 28, 2026 | A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service o | |
| CVE-2026-38350 | Hig | 7.5 | < 8.1.2-5.1 | 8.1.2-5.1 | Aug 28, 2026 | An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. | |
| CVE-2026-38349 | Hig | 7.5 | < 8.1.2-5.1 | 8.1.2-5.1 | Aug 28, 2026 | An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file. | |
| CVE-2026-38348 | Hig | 7.5 | < 8.1.2-5.1 | 8.1.2-5.1 | Aug 28, 2026 | An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file. | |
| CVE-2026-38347 | Hig | 7.5 | < 8.1.2-5.1 | 8.1.2-5.1 | Aug 28, 2026 | A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| CVE-2026-38346 | Hig | 7.5 | < 8.1.2-5.1 | 8.1.2-5.1 | Aug 28, 2026 | An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file. | |
| CVE-2026-38345 | Med | 6.5 | < 8.1.2-5.1 | 8.1.2-5.1 | Aug 28, 2026 | A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| CVE-2026-75147 | Hig | 7.1 | < 8.1.2-3.1 | 8.1.2-3.1 | Aug 19, 2026 | FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded header length plus the OBU payload | |
| CVE-2026-75146 | Hig | 8.1 | < 8.1.2-3.1 | 8.1.2-3.1 | Aug 19, 2026 | FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval functio | |
| CVE-2026-75145 | Med | 5.8 | < 8.1.2-3.1 | 8.1.2-3.1 | Aug 19, 2026 | FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison against the remaining frame size. On targets where long is 32 bits, including 64-bit Windows, suffi | |
| CVE-2026-75144 | Hig | 7.8 | < 8.1.2-3.1 | 8.1.2-3.1 | Aug 19, 2026 | FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies an input-derived data unit or | |
| CVE-2026-75143 | Cri | 9.8 | < 8.1.2-3.1 | 8.1.2-3.1 | Aug 19, 2026 | FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exce | |
| CVE-2026-75142 | Hig | 7.8 | < 8.1.2-3.1 | 8.1.2-3.1 | Aug 19, 2026 | FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams tri | |
| CVE-2026-75141 | Hig | 7.8 | < 8.1.2-3.1 | 8.1.2-3.1 | Aug 19, 2026 | FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC inp | |
| CVE-2026-70632 | Hig | 7.8 | < 8.1.2-3.1 | 8.1.2-3.1 | Aug 6, 2026 | FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() fun | |
| CVE-2026-70631 | Med | 5.5 | < 8.1.2-3.1 | 8.1.2-3.1 | Aug 6, 2026 | FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that te | |
| CVE-2026-70630 | Med | 5.5 | < 8.1.2-3.1 | 8.1.2-3.1 | Aug 6, 2026 | FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid | |
| CVE-2026-70629 | Med | 5.5 | < 8.1.2-3.1 | 8.1.2-3.1 | Aug 6, 2026 | FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decom | |
| CVE-2026-70628 | Hig | 7.8 | < 8.1.2-3.1 | 8.1.2-3.1 | Aug 6, 2026 | FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds- | |
| CVE-2026-66037 | Med | 6.5 | < 8.1.2-3.1 | 8.1.2-3.1 | Jul 24, 2026 | FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The |
- affected < 8.1.2-5.1fixed 8.1.2-5.1
A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service o
- affected < 8.1.2-5.1fixed 8.1.2-5.1
An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
- affected < 8.1.2-5.1fixed 8.1.2-5.1
An integer overflow in the hScale16To19_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.
- affected < 8.1.2-5.1fixed 8.1.2-5.1
An integer overflow in the libswscale/utils.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted image file.
- affected < 8.1.2-5.1fixed 8.1.2-5.1
A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.
- affected < 8.1.2-5.1fixed 8.1.2-5.1
An integer overflow in the yuv2planeX_8_c() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.
- affected < 8.1.2-5.1fixed 8.1.2-5.1
A Division-by-Zero vulnerability in the ff_sws_init_single_context function (/libswscale/utils.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
- affected < 8.1.2-3.1fixed 8.1.2-3.1
FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded header length plus the OBU payload
- affected < 8.1.2-3.1fixed 8.1.2-3.1
FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval functio
- affected < 8.1.2-3.1fixed 8.1.2-3.1
FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison against the remaining frame size. On targets where long is 32 bits, including 64-bit Windows, suffi
- affected < 8.1.2-3.1fixed 8.1.2-3.1
FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies an input-derived data unit or
- affected < 8.1.2-3.1fixed 8.1.2-3.1
FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exce
- affected < 8.1.2-3.1fixed 8.1.2-3.1
FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams tri
- affected < 8.1.2-3.1fixed 8.1.2-3.1
FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC inp
- affected < 8.1.2-3.1fixed 8.1.2-3.1
FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() fun
- affected < 8.1.2-3.1fixed 8.1.2-3.1
FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that te
- affected < 8.1.2-3.1fixed 8.1.2-3.1
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (libavcodec/screenpresso.c) that allows attackers to recover sensitive memory contents by supplying a crafted SPV1 packet with a valid
- affected < 8.1.2-3.1fixed 8.1.2-3.1
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decom
- affected < 8.1.2-3.1fixed 8.1.2-3.1
FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-
- affected < 8.1.2-3.1fixed 8.1.2-3.1
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The
Page 1 of 2