Executive brief
FFmpeg, a widely used multimedia framework for processing video and audio, contains a vulnerability in its RASC video decoder. By processing a specially crafted video file, an attacker can cause the software to write data outside of its intended memory boundaries. This can lead to application crashes, data corruption, or potentially allow an attacker to take control of the system running the software.
Technical details
An out-of-bounds (OOB) write vulnerability exists in FFmpeg's RASC video decoder, specifically within the 'decode_dlta' function in 'libavcodec/rasc.c'. The flaw stems from the decoder performing 32-bit reads and writes at the row cursor before verifying row boundaries (NEXT_LINE check) and validating the DLTA region in pixel units instead of byte units. When processing a PAL8 frame, a malicious DLTA run can access and overwrite memory several bytes past the allocated row buffer. An attacker can exploit this by providing a crafted media stream using the RASC FourCC, leading to bitstream-controlled heap corruption. A public proof-of-concept demonstrates that this can be used to hijack function pointers and achieve code execution.
Affected products
- FFmpeg FFmpeg <= bcd2c69e087a09b07cf45c6bd2428ee1ccb2925c (git)
Timeline
- 2026-06-26: other: Verified target on FFmpeg upstream master
- 2026-06-28: advisory: NVD publication date