Executive brief
A vulnerability exists in FFmpeg, a widely used framework for processing multimedia files. An attacker can provide a specially crafted input file to the zmqsend tool, which causes the application to fail to release system resources properly. This can lead to a denial-of-service condition, potentially crashing the software or making it unavailable for legitimate media processing tasks.
Technical details
A resource management vulnerability (CWE-400) exists in the tools/zmqsend.c component of FFmpeg version 8.0.1. The issue stems from improper resource deallocation and closure when processing input files. An attacker can exploit this by providing a specially crafted input file to the zmqsend utility, leading to uncontrolled resource consumption. This results in a Denial of Service (DoS) condition. The vulnerability is reachable over the network if the tool is used to process untrusted remote inputs, and it requires no specific privileges or user interaction to trigger.
Affected products
- FFmpeg FFmpeg 8.0.1
Timeline
- 2026-04-13: advisory: Initial disclosure of CVE-2026-30998