FFmpeg是FFmpeg组织开源的一套可录制、转换以及流化音视频的完整解决方案。 FFmpeg 2.7版本至8.1.2版本存在缓冲区错误漏洞,该漏洞源于TDSC视频解码器中的越界写入,tdsc_parse_tdsf()函数在调用av_frame_get_buffer()之前未能取消引用现有参考帧,导致tdsc_blit()和tdsc_yuv2rgb()将攻击者控制的像素数据写入超出小型参考帧缓冲区的末尾,可能允许远程攻击者通过提供特制的AVI文件造成堆损坏,导致进程崩溃并可能执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65706 | 7.8 HIGH | FFmpeg 3.0 - 8.1.2 vf_swaprect Out-of-Bounds Write via NV12 Frame Processing |
| CVE-2026-65705 | 7.8 HIGH | FFmpeg 3.4 - 8.1.2 vf_floodfill Out-of-Bounds Write via filter_frame() |
| CVE-2026-65704 | 7.8 HIGH | FFmpeg 8.1.2 Out-of-Bounds Write via TY Demuxer and Shorten Decoder |
No comments yet