OESA-2026-3082

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-3082
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-3082.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-3082
Upstream
  • CVE-2026-6385
Published
2026-07-19T11:11:58Z
Modified
2026-08-18T01:21:20.442348918Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
ffmpeg security update
Details

FFmpeg is a complete and free Internet live audio and video broadcasting solution for Linux/Unix. It also includes a digital VCR. It can encode in real time in many formats including MPEG1 audio and video, MPEG4, h263, ac3, asf, avi, real, mjpeg, and flash.

Security Fix(es):

A flaw was found in FFmpeg s TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists.(CVE-2023-6602)

Unchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C .

This issue affects FFmpeg: 7.1.

Issue was fixed:  https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a

https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman(CVE-2025-0518)

A NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/affirequalizer.c) due to a missing check on the return value of avmallocarray() in the configinput() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.(CVE-2025-10256)

A flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnnbackendtf.c source file. The issue occurs in the dnnexecutemodel_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.(CVE-2025-12343)

A vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ffaacsearchfortns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.(CVE-2025-1594)

A heap buffer overflow in the avbprintfinalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.(CVE-2026-30999)

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.(CVE-2026-40962)

A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds checks, leading to a heap out-of-bounds write. Successful exploitation can result in a denial of service (DoS) due to an application crash, and potentially lead to arbitrary code execution.(CVE-2026-6385)

Database specific
{
    "severity": "Critical"
}
References

Affected packages

openEuler:24.03-LTS-SP3 / ffmpeg

Package

Name
ffmpeg
Purl
pkg:rpm/openEuler/ffmpeg&distro=openEuler-24.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.1-35.oe2403sp3

Ecosystem specific

{
    "x86_64": [
        "ffmpeg-6.1.1-35.oe2403sp3.x86_64.rpm",
        "ffmpeg-debuginfo-6.1.1-35.oe2403sp3.x86_64.rpm",
        "ffmpeg-debugsource-6.1.1-35.oe2403sp3.x86_64.rpm",
        "ffmpeg-devel-6.1.1-35.oe2403sp3.x86_64.rpm",
        "ffmpeg-libs-6.1.1-35.oe2403sp3.x86_64.rpm",
        "libavdevice-6.1.1-35.oe2403sp3.x86_64.rpm"
    ],
    "aarch64": [
        "ffmpeg-6.1.1-35.oe2403sp3.aarch64.rpm",
        "ffmpeg-debuginfo-6.1.1-35.oe2403sp3.aarch64.rpm",
        "ffmpeg-debugsource-6.1.1-35.oe2403sp3.aarch64.rpm",
        "ffmpeg-devel-6.1.1-35.oe2403sp3.aarch64.rpm",
        "ffmpeg-libs-6.1.1-35.oe2403sp3.aarch64.rpm",
        "libavdevice-6.1.1-35.oe2403sp3.aarch64.rpm"
    ],
    "src": [
        "ffmpeg-6.1.1-35.oe2403sp3.src.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-3082.json"