Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-30998

Опубликовано: 13 апр. 2026
Источник: redhat
CVSS3: 5.3

Описание

An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.

A flaw was found in FFmpeg. An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component allows a remote attacker to cause a Denial of Service (DoS). By supplying a specially crafted input file, the attacker can trigger this flaw, leading to the application becoming unresponsive or crashing and disrupting service availability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Coreopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3ffmpegFix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3redhat-user-workloads/bootc-cuda-aws-3-3Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3redhat-user-workloads/bootc-cuda-azure-3-3Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3redhat-user-workloads/bootc-cuda-gcp-3-3Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3redhat-user-workloads/bootc-rocm-azure-3-3Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-vllm-gaudi-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2457861FFmpeg: FFmpeg: Denial of Service vulnerability in zmqsend.c via crafted input

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.

CVSS3: 7.5
nvd
4 месяца назад

An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.

CVSS3: 7.5
debian
4 месяца назад

An improper resource deallocation and closure vulnerability in the too ...

CVSS3: 7.5
github
4 месяца назад

An improper resource deallocation and closure vulnerability in the tools/zmqsend.c component of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input file.

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость утилиты zmqsend мультимедийной библиотеки FFmpeg, позволяющая нарушителю вызвать отказ в обслуживании

5.3 Medium

CVSS3