Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-18393

Опубликовано: 02 мая 2026
Источник: redhat
CVSS3: 5.4

Описание

A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service or arbitrary code execution.

Отчет

The ffmpeg package is not shipped in base Red Hat Enterprise Linux. It is available through EPEL, Red Hat Enterprise Linux AI, and as a bundled dependency in Red Hat OpenShift AI container images. The vulnerable code resides in libavcodec (tdsc.c), which is compiled and shipped in all FFmpeg builds across these products. The TDSC decoder is present since FFmpeg's initial inclusion of the codec in 2015.

Меры по смягчению последствий

Avoid opening untrusted TDSC-encoded video content with vulnerable FFmpeg consumers until a patched version is available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3ffmpegFix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-vllm-gaudi-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2520309ffmpeg: ffmpeg: Heap buffer overflow in tdsc_load_cursor() via CUR_FMT_MONO cursor

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
24 дня назад

A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service or arbitrary code execution.

CVSS3: 5.4
nvd
24 дня назад

A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service or arbitrary code execution.

CVSS3: 5.4
debian
24 дня назад

A flaw was found in FFmpeg. The tdsc_load_cursor() function writes bey ...

CVSS3: 5.4
github
24 дня назад

A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service or arbitrary code execution.

5.4 Medium

CVSS3