Description
A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting H.264/HEVC streams via RTP using a crafted input file. This was detected using AddressSanitizer.
Published: 2026-09-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A memory corruption vulnerability in FFmpeg prior to version 8.1 allows a crafted H.264 or HEVC RTP stream to cause a negative size value to be passed to memcpy, potentially overwriting internal data structures. This flaw stems from insufficient bounds checking during the nal_send function, exposing a buffer overflow condition that can lead to arbitrary code execution on the host executing FFmpeg. The weakness type is a classic out‑of‑bounds memory write.

Affected Systems

The vulnerability affects all FFmpeg releases before 8.1. It occurs in the libavformat/rtpenc_h264_hevc.c component when encoding H.264 or HEVC streams over RTP.

Risk and Exploitability

Based on the description, the likely attack vector is a malicious RTP stream or crafted input file processed by FFmpeg. The EPSS score is <1%, indicating a low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The CVSS score of 8.8 reflects high severity. If exploitable, it could allow remote code execution on the host running FFmpeg, giving the attacker full control.

Generated by OpenCVE AI on September 10, 2026 at 04:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade FFmpeg to version 8.1 or later.
  • If an upgrade cannot be applied immediately, restrict the use of H.264/HEVC RTP encoding or validate input streams to ensure size values are non‑negative before passing to FFmpeg.
  • Enable memory protection checks such as AddressSanitizer in a testing environment to detect similar regressions early.

Generated by OpenCVE AI on September 10, 2026 at 04:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Ffmpeg
Ffmpeg ffmpeg
Vendors & Products Ffmpeg
Ffmpeg ffmpeg

Thu, 10 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Title Memory Corruption in FFmpeg RTP Encoding Leading to Potential Remote Code Execution

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-787
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting H.264/HEVC streams via RTP using a crafted input file. This was detected using AddressSanitizer.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-09T15:18:09.979Z

Reserved: 2026-03-04T00:00:00.000Z

Link: CVE-2026-30754

cve-icon Vulnrichment

Updated: 2026-09-09T15:18:04.785Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T21:17:06.990

Modified: 2026-09-09T16:17:02.720

Link: CVE-2026-30754

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T08:00:12Z

Weaknesses