SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-38344

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A NULL pointer dereference vulnerability in the get_min_buffer_size function of FFmpeg can be exploited by attackers to trigger a Denial of Service (DoS) by providing a specially crafted video file. Organizations using FFmpeg for media processing should prioritize addressing this issue to prevent potential service disruptions.

CVE
CVE-2026-38344
Severity
HIGH
CVSS
7.5
EPSS
0.32%

Original NVD Description

A NULL pointer dereference in the get_min_buffer_size function (/libswscale/slice.c) of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.