FFmpeg Heap Buffer Overflow Vulnerability in av_bprint_finalize() Function Allowing Denial-of-Service

Vulnerability

A heap buffer overflow vulnerability has been identified in FFmpeg version 8.0.1. This vulnerability allows attackers to cause a denial-of-service (DoS) condition by exploiting the av_bprint_finalize() function with crafted input.

Impact

Exploitation of this vulnerability leads to a heap buffer overflow, causing a denial-of-service condition.

Reproduction

The vulnerability can be reproduced by sending a crafted input that triggers the heap buffer overflow in the av_bprint_finalize() function. This can be done using the FFmpeg tool 'zmqsend', which sends messages to a ZeroMQ recipient. The 'zmqsend' tool can be used to upload the malicious payload that exploits the vulnerability.

Remediation

Users are advised to upgrade to FFmpeg versions 8.1 or later, where this vulnerability has been addressed.

Added: Apr 13, 2026, 3:55 PM
Updated: Apr 13, 2026, 3:55 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
2.5
exploitability
5.7
remediation
0.0
relevance
5.8
threat
4.8
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.