CVE-2026-75147
Reported by VulnCheck · Published August 19, 2026
FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded header length plus the OBU payload size without first bounding the OBU size against the remaining data. A crafted OBU size causes the remaining-size counter to wrap to a positive value, causing the next loop iteration to dereference a pointer beyond the end of the packet buffer. A crafted AV1 input packet muxed to RTP triggers the out-of-bounds read.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| FFmpeg | FFmpeg | 0 |
| wolfi | ffmpeg-8.0 | 0, 0, 0 |
| chainguard | torchaudio-ffmpeg-tarballs | 0 |
| chainguard | ffmpeg-8.0 | 0 |
| chainguard | ffmpeg-9.0 | 0, 0 |
| FFmpeg | FFmpeg | 0, 0 |
| chainguard | eco-python-ffmpeg-8-minimal | 0 |
| chainguard | ffmpeg-7 | 0 |
| wolfi | ffmpeg-7.1 | *, *, * |
| wolfi | ffmpeg-7 | 0, 0, 0 |
| chainguard | eco-python-ffmpeg-6-minimal | 0 |
| wolfi | ffmpeg-9.0 | 0, 0, 0 |
| chainguard | ffmpeg-6 | *, * |
| chainguard | eco-python-ffmpeg-7-minimal | 0 |
| chainguard | ffmpeg-8.1 | 0, 0 |
| chainguard | ffmpeg-7.1 | *, * |
| wolfi | ffmpeg-8.1 | 0, 0, 0 |
Timeline
- Aug 19, 2026 CVE Published
- Aug 19, 2026 CVE Updated
- Aug 20, 2026 Coalition ESS Score
- Aug 24, 2026 EPSS Score
- Sep 4, 2026 Security Advisory
- Sep 24, 2026 EPSS Score
- Sep 25, 2026 EPSS Score
References
- Pull Request issue-tracking
- Patch Commit patch
- third-party-advisory