FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that searches for a sequence header OBU advanced its pointer and remaining-size counter by the encoded header length plus the OBU payload size without first bounding the OBU size against the remaining data. A crafted OBU size causes the remaining-size counter to wrap to a positive value, causing the next loop iteration to dereference a pointer beyond the end of the packet buffer. A crafted AV1 input packet muxed to RTP triggers the out-of-bounds read.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75147.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75147.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"275712041044194039918737384177752118465",
"112030629390621996673565528790491551613",
"168278039734422158952887987073227306153",
"7406117684115968516287365129868063248",
"282232263147983420017211581711086690635"
],
"threshold": 0.9
},
"id": "CVE-2026-75147-427036ae",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://code.ffmpeg.org/FFmpeg/FFmpeg@983dae9c19f46c87d597598c0fd2f2fcee0ad2f8",
"target": {
"file": "libavformat/rtpenc_av1.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "180879282261187805380209169201252525754",
"length": 5569
},
"id": "CVE-2026-75147-dca06188",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://code.ffmpeg.org/FFmpeg/FFmpeg@983dae9c19f46c87d597598c0fd2f2fcee0ad2f8",
"target": {
"file": "libavformat/rtpenc_av1.c",
"function": "ff_rtp_send_av1"
}
}
]
"2026-10-08T07:39:16Z"