Uncontrolled Resource Consumption in FFmpeg IAMF Demuxer
CVE-2026-66037
7.1HIGH
What is CVE-2026-66037?
FFmpeg versions up to 8.1.2 are affected by an uncontrolled resource consumption vulnerability in the IAMF demuxer. This flaw allows an unauthenticated attacker to exploit the system by providing a crafted count_label field that can trigger massive memory allocations. Specifically, the mix_presentation_obu() function does not properly validate the available data, leading to an amplification effect where a small input can result in multi-gigabyte memory usage. This issue may exhaust system memory, potentially resulting in an Out Of Memory (OOM) condition during format probing.
Affected Version(s)
FFmpeg 0 <= 8.1.2
FFmpeg 0 <= 8.1.2
FFmpeg 86708357d126af84c16f80d9c57335d1e8c845c5
