FFmpeg是FFmpeg组织开源的一套可录制、转换以及流化音视频的完整解决方案。 FFmpeg 8.1.2及之前版本存在资源管理错误漏洞,该漏洞源于IAMF demuxer中不受控制的资源消耗,mix_presentation_obu函数在libavformat/iamf_parse.c中调用av_calloc时使用攻击者控制的count_label值,在验证可用OBU数据前导致分配放大,可能使进程内存耗尽或触发OOM-kill。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66036 | 8.8 HIGH | FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter |
| CVE-2026-66040 | 8.8 HIGH | FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder |
| CVE-2026-66041 | 8.8 HIGH | FFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter |
| CVE-2026-66039 | 8.8 HIGH | FFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File |
| CVE-2026-66038 | 6.5 MEDIUM | FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c |
No comments yet