Description
An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.
Published: 2026-08-27
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an integer overflow in the libavfilter/vf_scale.c component of FFmpeg. Supplying a specially crafted video file can cause internal calculations to overflow, resulting in a crash or uncontrolled resource consumption. This leads directly to a denial of service which compromises availability of any system relying on FFmpeg to process media.

Affected Systems

All FFmpeg builds that use the legacy libavfilter/vf_scale.c implementation are affected. The exact affected release series is not enumerated in the advisory, so any FFmpeg deployment that has not applied a recent update or patch containing the fix is considered vulnerable.

Risk and Exploitability

The absence of an EPSS score or KEV listing limits public exploitation data, yet the nature of a DoS that can be triggered by arbitrary media input indicates a high impact. Exploitation would require access to a component that feeds user‑supplied video to FFmpeg, which is common in media servers, transcoding pipelines, and video editing applications. Attacking this vector could overwhelm resources, causing service outages.

Generated by OpenCVE AI on August 28, 2026 at 05:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the most recent FFmpeg release that includes the integer overflow patch
  • If upgrading cannot be performed immediately, sandbox the FFmpeg process and apply strict CPU, memory, and I/O limits while validating any incoming media before processing
  • Monitor for process crashes or abnormal resource usage and configure automatic restarts or fail‑over mechanisms

Generated by OpenCVE AI on August 28, 2026 at 05:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Ffmpeg
Ffmpeg ffmpeg
Vendors & Products Ffmpeg
Ffmpeg ffmpeg

Fri, 28 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in FFmpeg's Scale Filter Allows Denial of Service
Weaknesses CWE-680

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description An integer overflow in the libavfilter/vf_scale.c component of FFmpeg N-122528-gdd2976b9e1 allows attackers to cause a Denial of Service (DoS) via supplying a crafted video file.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-27T20:56:18.700Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38343

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T00:17:26.980

Modified: 2026-08-28T00:17:26.980

Link: CVE-2026-38343

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T09:45:17Z

Weaknesses
  • CWE-680

    Integer Overflow to Buffer Overflow