VDB

CVE-2026-75147

CVE-2026-75147 PUBLISHED CVSS 6.9 MEDIUM

Reported by VulnCheck · Published August 19, 2026

FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded header length plus the OBU payload size without first bounding the OBU size against the remaining data. A crafted OBU size causes the remaining-size counter to wrap to a positive value, causing the next loop iteration to dereference a pointer beyond the end of the packet buffer. A crafted AV1 input packet muxed to RTP triggers the out-of-bounds read.

Risk Scores

CVSS 4.0
6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Products

VendorProductVersions
FFmpegFFmpeg0
wolfiffmpeg-8.00, 0, 0
chainguardtorchaudio-ffmpeg-tarballs0
chainguardffmpeg-8.00
chainguardffmpeg-9.00, 0
FFmpegFFmpeg0, 0
chainguardeco-python-ffmpeg-8-minimal0
chainguardffmpeg-70
wolfiffmpeg-7.1*, *, *
wolfiffmpeg-70, 0, 0
chainguardeco-python-ffmpeg-6-minimal0
wolfiffmpeg-9.00, 0, 0
chainguardffmpeg-6*, *
chainguardeco-python-ffmpeg-7-minimal0
chainguardffmpeg-8.10, 0
chainguardffmpeg-7.1*, *
wolfiffmpeg-8.10, 0, 0

Timeline

  • Aug 19, 2026 CVE Published
  • Aug 19, 2026 CVE Updated
  • Aug 20, 2026 Coalition ESS Score
  • Aug 24, 2026 EPSS Score
  • Sep 4, 2026 Security Advisory
  • Sep 24, 2026 EPSS Score
  • Sep 25, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›