CyberRota Analysis
AI-GeneratedThe vulnerability affects FFmpeg versions up to 8.1.2, specifically within the vf_hqdn3d filter, allowing attackers to exploit heap out-of-bounds writes by supplying specially crafted videos. This can lead to heap memory corruption, potentially enabling remote code execution or denial of service. Users and organizations utilizing FFmpeg for video processing should prioritize patching to mitigate this high-severity risk.
Original NVD Description
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption.
Related CVEs
Other vulnerabilities affecting the same vendor(s)