Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-75147

8 дней назад

(FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 ...)

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2026-75147

8 дней назад

FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded header length plus the OBU payload size without first bounding the OBU size against the remaining data. A crafted OBU size causes the remaining-size counter to wrap to a positive value, causing the next loop iteration to dereference a pointer beyond the end of the packet buffer. A crafted AV1 input packet muxed to RTP triggers the out-of-bounds read.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2026-75147

8 дней назад

FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 ...

CVSS3: 7.1
EPSS: Низкий
github логотип

GHSA-63qj-83cj-jp3m

8 дней назад

FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded header length plus the OBU payload size without first bounding the OBU size against the remaining data. A crafted OBU size causes the remaining-size counter to wrap to a positive value, causing the next loop iteration to dereference a pointer beyond the end of the packet buffer. A crafted AV1 input packet muxed to RTP triggers the out-of-bounds read.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-75147

(FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 ...)

CVSS3: 7.1
0%
Низкий
8 дней назад
nvd логотип
CVE-2026-75147

FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded header length plus the OBU payload size without first bounding the OBU size against the remaining data. A crafted OBU size causes the remaining-size counter to wrap to a positive value, causing the next loop iteration to dereference a pointer beyond the end of the packet buffer. A crafted AV1 input packet muxed to RTP triggers the out-of-bounds read.

CVSS3: 7.1
0%
Низкий
8 дней назад
debian логотип
CVE-2026-75147

FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 ...

CVSS3: 7.1
0%
Низкий
8 дней назад
github логотип
GHSA-63qj-83cj-jp3m

FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded header length plus the OBU payload size without first bounding the OBU size against the remaining data. A crafted OBU size causes the remaining-size counter to wrap to a positive value, causing the next loop iteration to dereference a pointer beyond the end of the packet buffer. A crafted AV1 input packet muxed to RTP triggers the out-of-bounds read.

CVSS3: 7.1
0%
Низкий
8 дней назад

Уязвимостей на страницу