Executive brief
FFmpeg's convolution video filter is used to apply image processing effects (blur, edge detection, sharpening) to video streams. A flaw in boundary handling allows attackers to craft videos with dimensions smaller than the convolution kernel, causing the filter to read memory outside allocated buffers. This can lead to application crashes, denial of service, or information disclosure from sensitive memory regions.
Technical details
The vulnerability is a heap-buffer-overflow read (CWE-125) in the convolution filter's boundary reflection algorithm (setup_3x3, setup_5x5, setup_7x7, setup_row, setup_column functions in libavfilter/vf_convolution.c). When processing videos with dimensions smaller than the kernel size, the mirror reflection formula (xoff = 2*w - 1 - xoff) can produce negative array indices. The attack is network-reachable and requires no authentication; an attacker simply provides a specially crafted video file with insufficient height or width. Exploitation can trigger heap buffer overflow reads, causing information disclosure or crash. Patches are available in versions 4.4.7, 5.1.9, 6.1.5, 7.1.4, 8.0.2, 8.1.1, and 9.0, which replace the vulnerable algorithm with the avpriv_mirror function for correct boundary handling.
Affected products
- FFmpeg FFmpeg 4.4.6, 5.1.8, 6.1.4, 7.1.3, 8.0.1
Timeline
- 2026-09-14: disclosed: Public disclosure of CVE-2026-90815
- 2026-02-24: patched: Patch commit 8970658472 merged; versions 4.4.7, 5.1.9, 6.1.5, 7.1.4, 8.0.2, 8.1.1, and 9.0 contain the fix