Impact
A memory corruption vulnerability in FFmpeg prior to version 8.1 allows a crafted H.264 or HEVC RTP stream to cause a negative size value to be passed to memcpy, potentially overwriting internal data structures. This flaw stems from insufficient bounds checking during the nal_send function, exposing a buffer overflow condition that can lead to arbitrary code execution on the host executing FFmpeg. The weakness type is a classic out‑of‑bounds memory write.
Affected Systems
The vulnerability affects all FFmpeg releases before 8.1. It occurs in the libavformat/rtpenc_h264_hevc.c component when encoding H.264 or HEVC streams over RTP.
Risk and Exploitability
Based on the description, the likely attack vector is a malicious RTP stream or crafted input file processed by FFmpeg. The EPSS score is <1%, indicating a low but nonzero likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The CVSS score of 8.8 reflects high severity. If exploitable, it could allow remote code execution on the host running FFmpeg, giving the attacker full control.
OpenCVE Enrichment