Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-75143

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 8.8

Описание

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow by sending a packet whose payload exceeds the caller buffer size.

A flaw was found in FFmpeg. A heap buffer overflow in the RIST protocol reader allows a remote attacker to trigger memory corruption by sending an oversized packet to an FFmpeg instance receiving a RIST stream. The librist_read() function ignores its buffer size argument, copying the full payload into the caller-provided buffer without bounds checking. This could lead to denial of service or arbitrary code execution.

Отчет

The ffmpeg package is not shipped in base Red Hat Enterprise Linux. It is available through EPEL and Fedora with librist support enabled. Red Hat Enterprise Linux AI ships a reduced FFmpeg build that explicitly excludes librist, making the RIST code path unreachable. Red Hat OpenShift AI container images do not directly install FFmpeg. Exploitation requires the victim to be actively receiving a RIST stream, which is a niche broadcast video protocol not used in typical RH product deployments.

Меры по смягчению последствий

No mitigation is currently available for this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3ffmpegNot affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-vllm-gaudi-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2519758ffmpeg: FFmpeg Heap Buffer Overflow via RIST Protocol Reader

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
29 дней назад

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow by sending a packet whose payload exceeds the caller buffer size.

CVSS3: 9.8
nvd
29 дней назад

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow by sending a packet whose payload exceeds the caller buffer size.

CVSS3: 9.8
debian
29 дней назад

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RI ...

CVSS3: 9.8
github
29 дней назад

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow by sending a packet whose payload exceeds the caller buffer size.

suse-cvrf
4 дня назад

Security update for ffmpeg-4

8.8 High

CVSS3