A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read pointer into a decompressed buffer, but a subsequent reallocation of that same buffer during move-table processing leaves the pointer dangling. An attacker could exploit this by providing a specially crafted AVI file containing a malicious RASC video stream. When a user opens or plays the file, the decoder reads from freed heap memory, which could lead to a denial of service (crash).
CVSS Details
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade ffmpeg | Jun 21, 2026 | Jun 21, 2026 |
| Ffmpeg | — | Upgrade to FFmpeg version 9.0 | Sep 21, 2026 | Jun 19, 2026 |
| Ubuntu | — | Upgrade libavformat-extra58 (Ubuntu Pro)Upgrade libavcodec58 (Ubuntu Pro)Upgrade ffmpeg (Ubuntu Pro)Upgrade libavcodec-extra58 (Ubuntu Pro)Upgrade libavfilter7 (Ubuntu Pro)Upgrade libavformat58 (Ubuntu Pro) | Sep 14, 2026 | Sep 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub