Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-75146

Опубликовано: 19 авг. 2026
Источник: debian
EPSS Низкий

Описание

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ffmpegunfixedpackage
ffmpegpostponedtrixiepackage

Примечания

  • https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24093

  • Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/65b0dab903e5975e036b30ecc58f5935d4f151e0 (master)

  • Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/999f8ba75ce0bf1167677de7e11a5af678fdb866 (n9.0.1)

EPSS

Процентиль: 18%
0.00261
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
8 дней назад

(FFmpeg before commit 65b0dab contains an out-of-bounds read in the DAS ...)

CVSS3: 8.1
nvd
8 дней назад

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.

CVSS3: 8.1
github
8 дней назад

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.

EPSS

Процентиль: 18%
0.00261
Низкий