Impact
The vulnerability is an integer overflow in the libavfilter/vf_scale.c component of FFmpeg. Supplying a specially crafted video file can cause internal calculations to overflow, resulting in a crash or uncontrolled resource consumption. This leads directly to a denial of service which compromises availability of any system relying on FFmpeg to process media.
Affected Systems
All FFmpeg builds that use the legacy libavfilter/vf_scale.c implementation are affected. The exact affected release series is not enumerated in the advisory, so any FFmpeg deployment that has not applied a recent update or patch containing the fix is considered vulnerable.
Risk and Exploitability
The absence of an EPSS score or KEV listing limits public exploitation data, yet the nature of a DoS that can be triggered by arbitrary media input indicates a high impact. Exploitation would require access to a component that feeds user‑supplied video to FFmpeg, which is common in media servers, transcoding pipelines, and video editing applications. Attacking this vector could overwhelm resources, causing service outages.
OpenCVE Enrichment