Description
A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond
the bounds of a heap-allocated buffer when processing crafted TDSC cursor
data. A remote attacker could exploit this by supplying a specially crafted
video file, potentially leading to a denial of service or arbitrary code
execution.
Published: 2026-08-28
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FFmpeg contains a heap buffer overflow in the tdsc_load_cursor() function that processes TDSC cursor data. When a specially crafted video file containing malformed cursor payloads is decoded, the function writes past the end of a heap‑allocated buffer. This flaw can be exploited remotely by supplying such a video file, potentially leading to denial of service or arbitrary code execution on the system.

Affected Systems

Users running Red Hat Enterprise Linux AI 3 or Red Hat OpenShift AI have the affected FFmpeg packages. The vulnerability is present in the ffmpeg components bundled with these distributions.

Risk and Exploitability

With a CVSS score of 5.4, the vulnerability is classified as moderate severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. The attack requires only delivery of malicious TDSC‑encoded video content; therefore, it is likely to be exploitable from any context where FFmpeg consumes untrusted media, such as media servers, streaming services, or user‑uploaded videos. While no public exploits have been reported, the heap overrun is a classic use‑of‑pointer flaw (CWE‑787) that can lead to arbitrary code execution if an attacker can direct the overwrite.

Generated by OpenCVE AI on August 28, 2026 at 12:44 UTC.

Remediation

Vendor Workaround

Avoid opening untrusted TDSC-encoded video content with vulnerable FFmpeg consumers until a patched version is available.


OpenCVE Recommended Actions

  • Upgrade FFmpeg to the patched version provided by Red Hat for RHEL AI 3 or RHOAI.
  • If a patch is not yet available, configure applications or media services to refuse or skip processing of TDSC‑encoded video files.
  • Consider replacing or disabling FFmpeg components that handle cursor data in TDSC streams, or adjust content ingestion pipelines to filter out TDSC cursor payloads.

Generated by OpenCVE AI on August 28, 2026 at 12:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Ffmpeg
Ffmpeg ffmpeg
Red Hat
Red Hat red Hat Openshift Ai (rhoai)
Vendors & Products Ffmpeg
Ffmpeg ffmpeg
Red Hat
Red Hat red Hat Openshift Ai (rhoai)

Fri, 28 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service or arbitrary code execution.
Title Ffmpeg: ffmpeg: heap buffer overflow in tdsc_load_cursor() via cur_fmt_mono cursor
First Time appeared Redhat
Redhat enterprise Linux Ai
Redhat openshift Ai
Weaknesses CWE-787
CPEs cpe:/a:redhat:enterprise_linux_ai:3
cpe:/a:redhat:openshift_ai
Vendors & Products Redhat
Redhat enterprise Linux Ai
Redhat openshift Ai
References
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

Ffmpeg Ffmpeg
Red Hat Red Hat Openshift Ai (rhoai)
Redhat Enterprise Linux Ai Openshift Ai
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-08-28T09:21:17.392Z

Reserved: 2026-07-30T14:46:29.814Z

Link: CVE-2026-18393

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T12:16:25.943

Modified: 2026-08-28T12:16:25.943

Link: CVE-2026-18393

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T16:12:40Z

Weaknesses