CVE-2026-70629
EUVD-2026-5416106.08.2026, 22:18
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| ffmpeg | ffmpeg | 3.0 ≤ 𝑥 < 9 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
openSUSE / SLES Releases
openSUSE Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| libavcodec58_134 |
| ||||||||||||
| libavformat58_76 |
| ||||||||||||
| libavutil56_70 |
| ||||||||||||
| libpostproc55_9 |
| ||||||||||||
| libswresample3_9 |
| ||||||||||||
| libswscale5_9 |
|
Common Weakness Enumeration
References