FFmpeg 在 9.0.2 版本及之前,在 文件中的 函数存在栈耗尽漏洞。该函数会递归释放由 MOV 解复用器的 函数构建的 AVEncryptionInitInfo 链表。攻击者可以提供包含数万个小 pssh box(盒子)的精心构造的 MP4 文件,从而导致栈空间耗尽并使进程崩溃,同时还会引发二次方的 CPU 消耗问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107695 | 6.5 MEDIUM | FFmpeg before 8.1.3 HLS Demuxer Infinite Loop via Self-Referencing Playlist |
| CVE-2026-107696 | 6.5 MEDIUM | FFmpeg through 9.0.2 Infinite Loop via RTSP Redirect Handling in rtsp.c |
| CVE-2026-107675 | 5.9 MEDIUM | FFmpeg through 9.0.2 Missing SSH Host Key Verification in sftp Protocol |
| CVE-2026-107698 | 5.4 MEDIUM | FFmpeg before 7.1.4 and 8.0.2 SSRF via RTSP Redirect Handling |
| CVE-2026-107660 | 4.8 MEDIUM | FFmpeg before 8.1.3 and 9.x before 9.0.2 mbedTLS Hostname Verification Bypass for IP Hosts |
| CVE-2026-107677 | 4.7 MEDIUM | FFmpeg through 9.0.2 DASH Demuxer Infinite Loop via Empty SegmentTemplate Media |
| CVE-2026-107697 | 4.3 MEDIUM | FFmpeg before 8.1.3 HLS Demuxer Security Check Bypass via parse_playlist() |
| CVE-2026-107676 | 3.3 LOW | FFmpeg through 9.0.2 Uninitialized Memory Disclosure via HDR10+ Metadata Serializer |
No comments yet