FFmpeg是FFmpeg组织开源的一套可录制、转换以及流化音视频的完整解决方案。 FFmpeg 8.1.2及之前版本存在安全漏洞,该漏洞源于MACE6音频解码器中的有符号整数溢出,因为处理特制CAF文件时,desc chunk中的超大bytes_per_packet和frames_per_packet值在mace_decode_frame()中触发整数溢出,导致缓冲区分配不足和堆越界写入,可能允许攻击者执行代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-66036 | 8.8 HIGH | FFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter |
| CVE-2026-66040 | 8.8 HIGH | FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder |
| CVE-2026-66041 | 8.8 HIGH | FFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter |
| CVE-2026-66037 | 6.5 MEDIUM | FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu() |
| CVE-2026-66038 | 6.5 MEDIUM | FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c |
No comments yet