Heap Buffer Overflow in FFmpeg HEVC Configuration Writer
CVE-2026-75141

8.5HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-75141?

FFmpeg versions prior to commit acf5d7c are susceptible to a heap buffer overflow in the hvcC box writer. This vulnerability arises when writing an HEVC configuration record containing more NAL units of a single type than the count field can accurately represent. As a result, the NAL unit count overflows, leading to a heap buffer overflow condition. An attacker can exploit this flaw by crafting a malicious HEVC input file that triggers the overflow during the muxing process.

Affected Version(s)

FFmpeg 0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Joshua Rogers (AISLE Research)
.