Impact
The vulnerability in FFmpeg occurs during the decryption initialization step of MOV files. A malicious MP4 that contains thousands of extremely small pSSH boxes causes the demuxer’s mov_read_pssh() function to build a long linked list of AVEncryptionInitInfo structures. When the list is freed, the function av_encryption_init_info_free() recurses for each node, exhausting the process stack and triggering a crash. The recursion also leads to quadratic CPU usage, making the process vulnerable to performance denial of service.
Affected Systems
Any installation of FFmpeg 9.0.2 or earlier is susceptible, as the issue resides in libavformat/mov.c and libavutil/encryption_info.c for these releases.
Risk and Exploitability
The CVSS score of 5.7 reflects a moderate impact. Because the EPSS score is not available, the likelihood of exploitation is indeterminate from publicly available data. The vulnerability is not listed in the CISA KEV catalog, but the attack can be executed by feeding a crafted MP4 to any application that uses the vulnerable FFmpeg build. The path requires only local file input, making the risk appreciable for systems that process untrusted media.
OpenCVE Enrichment