Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-38350

Опубликовано: 27 авг. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

A flaw was found in FFmpeg. An integer overflow vulnerability in the target_sws_fuzzer() function allows a remote attacker to cause a Denial of Service (DoS) by supplying a specially crafted input. This can lead to the application becoming unresponsive or crashing, impacting its availability.

Отчет

The ffmpeg package is not shipped in base Red Hat Enterprise Linux. It is available through EPEL, Red Hat Enterprise Linux AI, and as a bundled dependency in Red Hat OpenShift AI container images. The vulnerable code resides in the bilinear interpolation routines of libswscale/output.c, which is core production code used by virtually all FFmpeg scaling operations. Despite the original CVE description referencing a function named 'target_sws_fuzzer', this is not a fuzzer-only issue — the integer overflows occur in production scaling code paths.

Меры по смягчению последствий

No mitigation is currently available for this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3ffmpegFix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-vllm-gaudi-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2525313ffmpeg: FFmpeg: Integer overflow leads to Denial of Service

EPSS

Процентиль: 25%
0.00324
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
17 дней назад

An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

CVSS3: 7.5
nvd
17 дней назад

An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

CVSS3: 7.5
debian
17 дней назад

An integer overflow in the target_sws_fuzzer() function (libswscale/ou ...

CVSS3: 7.5
github
17 дней назад

An integer overflow in the target_sws_fuzzer() function (libswscale/output.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.

EPSS

Процентиль: 25%
0.00324
Низкий

5.5 Medium

CVSS3