Executive brief
FFmpeg is a widely used software library for processing video, audio, and other multimedia files. A security flaw has been identified that allows an attacker to crash applications using this library by providing a specially crafted media file or input. This could lead to a service outage or 'Denial of Service' for any platform or tool that relies on FFmpeg to handle user-uploaded content.
Technical details
A heap-based buffer overflow (CWE-122) exists in FFmpeg v8.0.1 within the av_bprint_finalize() function, located in libavutil/bprint.c. The vulnerability is triggered when processing specially crafted input, potentially through tools like zmqsend that utilize the AVBPrint interface for string handling. An unauthenticated remote attacker can exploit this by providing malicious input that exceeds allocated buffer boundaries during the finalization of a print buffer. This results in memory corruption and a subsequent application crash (Denial of Service). While the advisory mentions version 8.0.1, users should look toward version 8.0.2 or 8.1.1 for potential fixes.
Affected products
- FFmpeg FFmpeg 8.0.1
Timeline
- 2026-04-13: advisory: Initial disclosure of CVE-2026-30999