Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-75142

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.

A flaw was found in FFmpeg. A stack buffer overflow exists in the MPEG-PS muxer. A local attacker or a user processing a specially crafted file with an excessive number of streams could trigger this flaw, leading to a buffer overflow. This could potentially result in denial of service or arbitrary code execution.

Отчет

The ffmpeg package is not shipped in base Red Hat Enterprise Linux. It is available through EPEL, Red Hat Enterprise Linux AI, and as a bundled dependency in Red Hat OpenShift AI container images. The vulnerable code resides in the MPEG-PS muxer (libavformat/mpegenc.c), which is compiled and shipped in all FFmpeg builds across these products. This is a stack buffer overflow triggered by input with an excessive number of streams.

Меры по смягчению последствий

No mitigation is currently available for this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3ffmpegFix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-vllm-gaudi-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2519759ffmpeg: FFmpeg: Stack Buffer Overflow in MPEG-PS Muxer

EPSS

Процентиль: 3%
0.00137
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
29 дней назад

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.

CVSS3: 7.8
nvd
29 дней назад

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.

CVSS3: 7.8
debian
29 дней назад

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the M ...

CVSS3: 7.8
github
29 дней назад

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.

suse-cvrf
4 дня назад

Security update for ffmpeg-4

EPSS

Процентиль: 3%
0.00137
Низкий

7.8 High

CVSS3

Уязвимость CVE-2026-75142