A heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ffmpeg | — | Upgrade to FFmpeg version 9.0Upgrade to FFmpeg version 8.0.3Upgrade to FFmpeg version 8.1.2 | Apr 27, 2026 | Apr 13, 2026 |
| Ubuntu | — | Upgrade libavformat-extra58 (Ubuntu Pro)Upgrade libavfilter7 (Ubuntu Pro)Upgrade libavcodec58 (Ubuntu Pro)Upgrade ffmpeg (Ubuntu Pro)Upgrade libavcodec-extra58 (Ubuntu Pro)Upgrade libavformat58 (Ubuntu Pro) | Sep 14, 2026 | Sep 14, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub