Memory Corruption Vulnerability in FFmpeg RTP Encoding for H.264/HEVC
CVE-2026-30754

8.8HIGH

Key Information:

Vendor

FFmpeg

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-30754?

A memory corruption vulnerability is present in FFmpeg prior to version 8.1. The issue arises during the RTP encoding process in the nal_send function located in libavformat/rtpenc_h264_hevc.c. Specifically, a negative size parameter (-3) is passed to the memcpy function when handling H.264/HEVC streams with crafted input files. This flaw can lead to unexpected behavior and potential exploitation, as identified through testing with AddressSanitizer.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.