Impact
A remote attacker can trigger an out-of-bounds read in the setup_3x3 function of FFmpeg’s convolution filter, causing sensitive data to be read from memory. The flaw corresponds to CWE-119 (Buffer Access After Free/Out-of-Bounds) and CWE-125 (Out-of-Bounds Read). Depending on the context, information leakage could expose system memory or media content processed by FFmpeg.
Affected Systems
FFmpeg users employing the convolution filter up through versions 4.4.6, 5.1.8, 6.1.4, 7.1.3, and 8.0.1 are vulnerable. Patch releases 4.4.7, 5.1.9, 6.1.5, 7.1.4, 8.0.2, 8.1.1, and 9.0 contain the fix.
Risk and Exploitability
The CVSS score is 5.3, indicating a moderate impact. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, but the remote exploitation path and public disclosure suggest it could be used in the wild. Immediate patching reduces the risk of data exposure until a comprehensive mitigation is applied.
OpenCVE Enrichment