Executive brief
FFmpeg, a widely used multimedia framework for processing video and audio, contains a flaw in its TDSC video decoder. An attacker can exploit this by providing a specially crafted AVI video file that, when opened by a user, causes the application to crash or potentially allow the execution of unauthorized code. This could lead to a compromise of the user's system or a disruption of services that process automated video uploads.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the FFmpeg TDSC video decoder due to improper memory management during frame dimension changes. The function 'tdsc_parse_tdsf' fails to unreference an existing reference frame before calling 'av_frame_get_buffer', which leads to the reuse of stale stride (linesize) information. When 'tdsc_blit' or 'tdsc_yuv2rgb' subsequently write pixel data to the newly allocated but undersized buffer, they write beyond its boundaries. This local attack requires a user to open a malformed AVI file and can result in heap corruption, process crashes, or arbitrary code execution. The issue is addressed by ensuring 'av_frame_unref' is called before reallocation.
Affected products
- FFmpeg FFmpeg 2.7 through 8.1.2
Timeline
- 2026-07-10: patched: Fix committed to FFmpeg repository
- 2026-07-23: disclosed: Vulnerability published in NVD and VulnCheck