Description
FFmpeg through 9.0.2 contains a stack exhaustion vulnerability in av_encryption_init_info_free() in libavutil/encryption_info.c, which recursively frees AVEncryptionInitInfo linked lists built by the MOV demuxer's mov_read_pssh(). Attackers can supply a crafted MP4 file with tens of thousands of small pssh boxes to exhaust the stack and crash the process, while also causing quadratic CPU consumption.
Published: 2026-10-08
Score: 5.7 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service (stack exhaustion and high CPU consumption)
Action: Patch
AI Analysis

Impact

The vulnerability in FFmpeg occurs during the decryption initialization step of MOV files. A malicious MP4 that contains thousands of extremely small pSSH boxes causes the demuxer’s mov_read_pssh() function to build a long linked list of AVEncryptionInitInfo structures. When the list is freed, the function av_encryption_init_info_free() recurses for each node, exhausting the process stack and triggering a crash. The recursion also leads to quadratic CPU usage, making the process vulnerable to performance denial of service.

Affected Systems

Any installation of FFmpeg 9.0.2 or earlier is susceptible, as the issue resides in libavformat/mov.c and libavutil/encryption_info.c for these releases.

Risk and Exploitability

The CVSS score of 5.7 reflects a moderate impact. Because the EPSS score is not available, the likelihood of exploitation is indeterminate from publicly available data. The vulnerability is not listed in the CISA KEV catalog, but the attack can be executed by feeding a crafted MP4 to any application that uses the vulnerable FFmpeg build. The path requires only local file input, making the risk appreciable for systems that process untrusted media.

Generated by OpenCVE AI on October 8, 2026 at 17:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update FFmpeg to 9.0.3 or later, which removes the recursive free in av_encryption_init_info_free()
  • If an immediate upgrade is not possible, sanitize or reject MP4 files that contain large numbers of pSSH boxes before passing them to FFmpeg
  • Configure monitoring to detect crashes or abnormal CPU spikes during MP4 decoding to identify exploitation attempts

Generated by OpenCVE AI on October 8, 2026 at 17:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 15:45:00 +0000

Type Values Removed Values Added
Description FFmpeg through 9.0.2 contains a stack exhaustion vulnerability in av_encryption_init_info_free() in libavutil/encryption_info.c, which recursively frees AVEncryptionInitInfo linked lists built by the MOV demuxer's mov_read_pssh(). Attackers can supply a crafted MP4 file with tens of thousands of small pssh boxes to exhaust the stack and crash the process, while also causing quadratic CPU consumption.
Title FFmpeg through 9.0.2 Stack Exhaustion via Recursive Free of pssh Boxes
First Time appeared Ffmpeg
Ffmpeg ffmpeg
Weaknesses CWE-674
CPEs cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Vendors & Products Ffmpeg
Ffmpeg ffmpeg
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 5.7, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T17:51:49.706Z

Reserved: 2026-10-08T15:11:28.450Z

Link: CVE-2026-107678

cve-icon Vulnrichment

Updated: 2026-10-08T16:00:33.288Z

cve-icon NVD

Status : Received

Published: 2026-10-08T16:17:05.747

Modified: 2026-10-08T18:17:25.740

Link: CVE-2026-107678

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T18:00:18Z

Weaknesses