Описание
An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| ffmpeg | fixed | 7:8.1.1-1 | package | |
| ffmpeg | postponed | bullseye | package |
Примечания
https://excellent-oatmeal-319.notion.site/CVE-2026-30997-Out-of-Bounds-Access-a7929817b9794568b2f7774397c7d65f
Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/1a2c16fe514b60e1860829c42ce199de77a007e5
Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/6266867e7bc4106dd3f77d6d702a0499fb3254db (n8.1.1)
Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/3c4ca300f469d657051c8584515870fe9c36aaa3 (n8.0.2)
Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/9abe92e3af7fa7becc8f7f742b1457b4c28220a6 (n7.1.4)
Fixed by: https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/74c75e9ceacd99d20c09d09fec73c1b15ffd6172 (n5.1.9)
EPSS
Связанные уязвимости
An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
An out-of-bounds read in the read_global_param() function (libavcodec/av1dec.c) of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
EPSS