Description
A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component Convolution Filter. Such manipulation leads to out-of-bounds read. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.4.7, 5.1.9, 6.1.5, 7.1.4, 8.0.2, 8.1.1 and 9.0 can resolve this issue. The name of the patch is 8970658472/e24b9820b4. It is suggested to upgrade the affected component.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Leak
Action: Patch Now
AI Analysis

Impact

A remote attacker can trigger an out-of-bounds read in the setup_3x3 function of FFmpeg’s convolution filter, causing sensitive data to be read from memory. The flaw corresponds to CWE-119 (Buffer Access After Free/Out-of-Bounds) and CWE-125 (Out-of-Bounds Read). Depending on the context, information leakage could expose system memory or media content processed by FFmpeg.

Affected Systems

FFmpeg users employing the convolution filter up through versions 4.4.6, 5.1.8, 6.1.4, 7.1.3, and 8.0.1 are vulnerable. Patch releases 4.4.7, 5.1.9, 6.1.5, 7.1.4, 8.0.2, 8.1.1, and 9.0 contain the fix.

Risk and Exploitability

The CVSS score is 5.3, indicating a moderate impact. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, but the remote exploitation path and public disclosure suggest it could be used in the wild. Immediate patching reduces the risk of data exposure until a comprehensive mitigation is applied.

Generated by OpenCVE AI on September 15, 2026 at 12:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FFmpeg to a patched version (4.4.7 or later), as listed in the advisory.
  • If the convolution filter is not essential to your workflow, disable or remove it from your processing pipeline to eliminate the vulnerable code path.
  • Regularly review system logs for unauthorized media processing activity and monitor for anomalous memory usage patterns.

Generated by OpenCVE AI on September 15, 2026 at 12:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in FFmpeg up to 4.4.6/5.1.8/6.1.4/7.1.3/8.0.1. Affected by this issue is the function setup_3x3 of the file libavfilter/vf_convolution.c of the component Convolution Filter. Such manipulation leads to out-of-bounds read. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 4.4.7, 5.1.9, 6.1.5, 7.1.4, 8.0.2, 8.1.1 and 9.0 can resolve this issue. The name of the patch is 8970658472/e24b9820b4. It is suggested to upgrade the affected component.
Title FFmpeg Convolution Filter vf_convolution.c setup_3x3 out-of-bounds
First Time appeared Ffmpeg
Ffmpeg ffmpeg
Weaknesses CWE-119
CWE-125
CPEs cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Vendors & Products Ffmpeg
Ffmpeg ffmpeg
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:41:43.586Z

Reserved: 2026-09-13T16:31:59.613Z

Link: CVE-2026-90815

cve-icon Vulnrichment

Updated: 2026-09-15T14:41:21.695Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:17:02.920

Modified: 2026-09-15T15:17:29.857

Link: CVE-2026-90815

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-14T19:45:05Z

Links: CVE-2026-90815 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T12:30:13Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-125

    Out-of-bounds Read