Executive brief
FFmpeg, a widely used multimedia framework for processing audio and video, contains a flaw in how it handles certain immersive audio files. An attacker can provide a specially crafted, tiny audio file that forces the software to attempt to allocate massive amounts of system memory. This can lead to the application crashing or the entire system becoming unresponsive, potentially disrupting media processing services or applications that rely on FFmpeg.
Technical details
An uncontrolled resource consumption vulnerability exists in the IAMF (Immersive Audio Model and Formats) demuxer within FFmpeg. The root cause is located in the mix_presentation_obu() function in libavformat/iamf_parse.c, which calls av_calloc() using an attacker-controlled count_label value before validating the available OBU data. This results in an allocation amplification of approximately 126 million bytes per input byte. An unauthenticated remote attacker can exploit this by providing a crafted 17-byte input file, leading to process memory exhaustion or an Out-of-Memory (OOM) kill during format probing. The issue is fixed in commit 86708357d1 (referenced as 5d7112c in some contexts).
Affected products
- FFmpeg FFmpeg through 8.1.2
Timeline
- 2026-06-28: patched: Fix committed to master branch
- 2026-07-24: disclosed: CVE published and advisory released by VulnCheck