Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-30999

Опубликовано: 13 апр. 2026
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

A flaw was found in FFmpeg. A remote attacker could exploit a heap buffer overflow vulnerability in the av_bprint_finalize() function by providing a specially crafted input. This could lead to a Denial of Service (DoS), making the affected system or application unavailable to legitimate users.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed Coreopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3ffmpegFix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3redhat-user-workloads/bootc-cuda-aws-3-3Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3redhat-user-workloads/bootc-cuda-azure-3-3Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3redhat-user-workloads/bootc-cuda-gcp-3-3Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3redhat-user-workloads/bootc-rocm-azure-3-3Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Fix deferred
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-vllm-gaudi-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2457860FFmpeg: FFmpeg: Denial of Service via heap buffer overflow in av_bprint_finalize()

EPSS

Процентиль: 37%
0.00452
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
nvd
4 месяца назад

A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
debian
4 месяца назад

A heap buffer overflow in the av_bprint_finalize() function of FFmpeg ...

CVSS3: 7.5
github
4 месяца назад

A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость функции av_bprint_finalize() утилиты zmqsend мультимедийной библиотеки FFmpeg, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 37%
0.00452
Низкий

5.3 Medium

CVSS3