Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40962

Опубликовано: 16 апр. 2026
Источник: redhat
CVSS3: 4.8

Описание

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

A flaw was found in FFmpeg. This vulnerability, stemming from an integer overflow and a subsequent out-of-bounds write during the processing of Common Encryption (CENC) subsample data, could allow a local attacker to potentially trigger information disclosure, data corruption, or a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Lightspeed CoreffmpegAffected
Lightspeed Corelightspeed-core/rag-tool-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3ffmpegAffected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-aws-cuda-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-azure-cuda-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-azure-rocm-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-cuda-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-gcp-cuda-rhel9Affected
Red Hat Enterprise Linux AI (RHEL AI) 3rhelai3/bootc-rocm-rhel9Affected
Red Hat OpenShift AI (RHOAI)ffmpegAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2458862FFmpeg: FFmpeg: Integer overflow and out-of-bounds write via CENC subsample data

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.9
ubuntu
4 месяца назад

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

CVSS3: 4.9
nvd
4 месяца назад

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

CVSS3: 4.9
debian
4 месяца назад

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds ...

suse-cvrf
3 месяца назад

Security update for ffmpeg-4

CVSS3: 4.9
github
4 месяца назад

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

4.8 Medium

CVSS3