FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is cast to long before comparison against the remaining frame size. On targets where long is 32 bits, including 64-bit Windows, sufficiently large OBU size values are sign-flipped by the narrowing cast, producing a negative value that passes the payload size check. This allows an oversized OBU to bypass the safety bound on affected platforms, leading to out-of-bounds memory access when the oversized value is subsequently used as a copy length.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-681"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75145.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75145.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"123634740780764270793455847189449018004",
"200791457857056029392735313457550745953",
"110406273147403960171518331405757524532",
"235082650345161628829360297442450494455"
],
"threshold": 0.9
},
"id": "CVE-2026-75145-6e3cad5c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://code.ffmpeg.org/FFmpeg/FFmpeg@b4c199c5906ff53368926c2a5839881f41957e7f",
"target": {
"file": "libavformat/rtpenc_av1.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "218633532821867766148620393634019614045",
"length": 5625
},
"id": "CVE-2026-75145-bdcb4dba",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://code.ffmpeg.org/FFmpeg/FFmpeg@b4c199c5906ff53368926c2a5839881f41957e7f",
"target": {
"file": "libavformat/rtpenc_av1.c",
"function": "ff_rtp_send_av1"
}
}
]
"2026-10-08T07:39:15Z"