Executive brief
FFmpeg's MPEG-PS muxer contains a buffer overflow vulnerability that can be triggered by processing media files with excessive numbers of streams. An attacker who provides a maliciously crafted file with many streams could cause FFmpeg to crash or potentially execute arbitrary code on a system using the library for video processing or transcoding.
Technical details
A stack buffer overflow exists in libavformat/mpegenc.c within the put_system_header() function. The function writes 12 + 3*N bytes (where N is the number of streams) to a fixed 128-byte stack buffer, and approximately 35+ streams will cause an overflow. The vulnerability occurs because put_system_header() is handed a PutBitContext sized past the real buffer, causing its own bounds check to fail. The fix, committed as 9d786e4, adds validation at muxer initialization to reject configurations where the system header would not fit within the available 128-byte buffer space. Attack requires network access if FFmpeg is used in a service, or local access if processing untrusted files. No authentication is required.
Affected products
- FFmpeg FFmpeg before commit 9d786e4
Timeline
- 2026-08-19: disclosed
- 2026-08-11: patched: Fix merged in commit 9d786e4