Stack Exhaustion Vulnerability in FFmpeg by Leading Multimedia Vendor
CVE-2026-107678

5.7MEDIUM

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-107678?

The stack exhaustion vulnerability in FFmpeg through version 9.0.2 exists within the av_encryption_init_info_free() function in libavutil/encryption_info.c. This vulnerability is triggered when attackers exploit the MOV demuxer's mov_read_pssh() function by supplying a specially crafted MP4 file filled with numerous small pssh boxes. The crafted file leads to recursive freeing of AVEncryptionInitInfo linked lists, which can deplete the stack space, resulting in a process crash and causing excessive CPU consumption due to the quadratic time complexity of this action.

Affected Version(s)

FFmpeg 0 <= 9.0.2

References

CVSS V4

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joshua Rogers (AISLE Research)
.