Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-64833

Опубликовано: 22 июл. 2026
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Версия от 0.7.1 (включая) до 8.1.2 (включая)

EPSS

Процентиль: 12%
0.00214
Низкий

7.1 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.1
ubuntu
12 дней назад

FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.

CVSS3: 7.1
debian
12 дней назад

FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vuln ...

CVSS3: 7.1
github
12 дней назад

FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.

EPSS

Процентиль: 12%
0.00214
Низкий

7.1 High

CVSS3

Дефекты

CWE-125