Описание
An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.
A flaw was found in FFmpeg. An integer overflow in the libavfilter/vf_scale.c component allows attackers to cause a Denial of Service (DoS) by supplying a specially crafted video file. This can lead to the application becoming unresponsive or crashing.
Отчет
The ffmpeg package is not shipped in base Red Hat Enterprise Linux. It is available through EPEL, Red Hat Enterprise Linux AI, and as a bundled dependency in Red Hat OpenShift AI container images. The vulnerable code resides in libavfilter, which is compiled and shipped in all FFmpeg builds across these products. This vulnerability has low practical impact as FFmpeg already rejects the invalid output size with an error; the integer overflow is undefined behavior detected by sanitizers but does not result in memory corruption.
Меры по смягчению последствий
No mitigation is currently available for this flaw.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux AI (RHEL AI) 3 | ffmpeg | Fix deferred | ||
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-vllm-gaudi-rhel9 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.5 Medium
CVSS3
Связанные уязвимости
An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.
An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.
An integer overflow in the libavfilter/vf_scale.c component of FFmpeg ...
An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.
EPSS
5.5 Medium
CVSS3