Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-75146

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 8.1

Описание

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.

A flaw was found in FFmpeg. A malicious or misconfigured DASH (Dynamic Adaptive Streaming over HTTP) server can exploit an out-of-bounds read vulnerability in the DASH demuxer. This occurs when a live DASH manifest is refreshed with a startNumber that is lower than the previous value, causing a negative index to be used in the fragment retrieval function. Successful exploitation could lead to information disclosure or a denial of service.

Отчет

The ffmpeg package is not shipped in base Red Hat Enterprise Linux. It is available through EPEL, Red Hat Enterprise Linux AI, and as a bundled dependency in Red Hat OpenShift AI container images. The vulnerable code resides in the DASH demuxer (libavformat/dashdec.c), which is compiled and shipped in all FFmpeg builds across these products. Exploitation requires a malicious or misconfigured DASH server to serve a live manifest with a decreasing startNumber across a refresh.

Меры по смягчению последствий

No mitigation is currently available for this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux AI (RHEL AI) 3ffmpegFix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-vllm-gaudi-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2519764ffmpeg: FFmpeg: Information disclosure and denial of service via out-of-bounds read in DASH demuxer

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
29 дней назад

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.

CVSS3: 8.1
nvd
29 дней назад

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.

CVSS3: 8.1
debian
29 дней назад

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DAS ...

CVSS3: 8.1
github
29 дней назад

FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.

suse-cvrf
4 дня назад

Security update for ffmpeg-4

8.1 High

CVSS3