Heap Buffer Overflow in FFmpeg HEVC Configuration Writer
CVE-2026-75141
8.5HIGH
What is CVE-2026-75141?
FFmpeg versions prior to commit acf5d7c are susceptible to a heap buffer overflow in the hvcC box writer. This vulnerability arises when writing an HEVC configuration record containing more NAL units of a single type than the count field can accurately represent. As a result, the NAL unit count overflows, leading to a heap buffer overflow condition. An attacker can exploit this flaw by crafting a malicious HEVC input file that triggers the overflow during the muxing process.
Affected Version(s)
FFmpeg 0
