Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-75141

Опубликовано: 19 авг. 2026
Источник: debian
EPSS Низкий

Описание

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegunfixedpackage
ffmpegpostponedtrixiepackage

Примечания

  • https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24088

  • Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781 (master)

  • Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c7132ef8f63c383d11a00a9e3034748d8dd15fb3 (n9.0.1)

EPSS

Процентиль: 3%
0.00137
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
8 дней назад

(FFmpeg before commit acf5d7c contains a heap buffer overflow in the hv ...)

CVSS3: 7.8
nvd
8 дней назад

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.

CVSS3: 7.8
github
8 дней назад

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.

EPSS

Процентиль: 3%
0.00137
Низкий