Stack Exhaustion Vulnerability in FFmpeg by Leading Multimedia Vendor
CVE-2026-107678
5.7MEDIUM
What is CVE-2026-107678?
The stack exhaustion vulnerability in FFmpeg through version 9.0.2 exists within the av_encryption_init_info_free() function in libavutil/encryption_info.c. This vulnerability is triggered when attackers exploit the MOV demuxer's mov_read_pssh() function by supplying a specially crafted MP4 file filled with numerous small pssh boxes. The crafted file leads to recursive freeing of AVEncryptionInitInfo linked lists, which can deplete the stack space, resulting in a process crash and causing excessive CPU consumption due to the quadratic time complexity of this action.
Affected Version(s)
FFmpeg 0 <= 9.0.2
