Impact
FFmpeg up to version 9.0.2 includes a flaw (CWE-835) in the DASH demuxer that allows a crafted .mpd manifest with an empty SegmentTemplate media attribute to trigger an infinite loop. The loop occurs when get_current_fragment() calls a string replacement routine with a zero‑length search string, causing the demuxer to consume CPU cycles indefinitely. This denial of service can be triggered simply by providing the malformed manifest to FFmpeg's media parsing function.
Affected Systems
The vulnerability impacts the FFmpeg project, specifically all releases up through 9.0.2. Deployments of FFmpeg that use the DASH demuxer for processing media should consider this risk if they accept external manifest files. Earlier versions before 9.0.2 are also affected, as the code path is unchanged.
Risk and Exploitability
The CVSS score is 5.7, indicating moderate severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog, suggesting that routine exploitation is not currently observed. The likely attack vector involves providing a malicious manifest to an instance of FFmpeg that processes DASH streams, which can occur as a remote or local attack by an adversary who controls media input. With no known mitigations beyond updating, an attacker can exhaust CPU resources and potentially disrupt service availability.
OpenCVE Enrichment