Junglewise Threat Intelligence

CVE-2026-38346: FFmpeg integer overflow in yuv2planeX_8_c

CVE-2026-38346 · Severity: high · CVSS 7.5 · Published 2026-08-28

Technologies: Ffmpeg. Vendors: Ffmpeg.

Executive brief

FFmpeg is a widely-used multimedia framework that processes video and audio files. An integer overflow flaw in the video scaling component can be triggered by supplying a specially crafted video file with extreme scaling parameters, causing the application to crash or become unresponsive. This could disrupt video transcoding services or applications that rely on FFmpeg for media processing.

Technical details

A signed integer overflow exists in the yuv2planeX_8_c() function within libswscale/output.c at line 477, where accumulated filter coefficients (val += src[j][i] * filter[j]) exceed INT_MAX (2147483647). The vulnerability is triggered by extreme downscaling ratios (such as 681:1) using the SINC filter algorithm, which generates large filter sizes and coefficients. The 16-bit version of this function at line 183 correctly uses int64_t accumulators with unsigned casts to prevent overflow, but the 8-bit version lacks this protection. An attacker can cause a Denial of Service by providing a crafted video file with extreme scaling parameters. No patch availability information was provided in the advisory; affected deployments should monitor FFmpeg releases for a fix.

Affected products

  • FFmpeg FFmpeg N-122528-gdd2976b9e1 and likely other versions

Timeline

  • 2026-08-28: disclosed
  • 2026-01-26: other: Bug report filed

References

Related threats