Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-38347

Опубликовано: 27 авг. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.

A flaw was found in FFmpeg. A heap overflow vulnerability exists in the ff_sws_alphablendaway function. This flaw allows attackers to cause a Denial of Service (DoS) by providing a specially crafted input. Successful exploitation could lead to the application becoming unresponsive or crashing.

Отчет

The ffmpeg package is not shipped in base Red Hat Enterprise Linux. It is available through EPEL, Red Hat Enterprise Linux AI, and as a bundled dependency in Red Hat OpenShift AI container images. The vulnerable code resides in libswscale, which is compiled and shipped in all FFmpeg builds across these products. This is a heap overflow rather than a simple denial of service, which could potentially have higher impact if the overflow is controllable by an attacker.

Меры по смягчению последствий

No mitigation is currently available for this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3ffmpegFix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-vllm-gaudi-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2525314ffmpeg: FFmpeg: Heap overflow vulnerability leads to Denial of Service

EPSS

Процентиль: 26%
0.00329
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
17 дней назад

A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
nvd
17 дней назад

A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.

CVSS3: 7.5
debian
17 дней назад

A heap overflow in the ff_sws_alphablendaway function (libswscale/alph ...

CVSS3: 7.5
github
17 дней назад

A heap overflow in the ff_sws_alphablendaway function (libswscale/alphablend.c) of FFmpeg git-master commit 722a217 allows attackers to cause a Denial of Service (DoS) via a crafted input.

EPSS

Процентиль: 26%
0.00329
Низкий

5.5 Medium

CVSS3