← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 19, 2026 · 16:26via CVEFeed

CVE-2026-75144 - FFmpeg Heap Buffer Overflow in VC-2/Dirac RTP Packetizer

Brief

CVE ID : CVE-2026-75144

Published : Aug. 19, 2026, 4:26 p. m.

  • 42 minutes ago

Description : FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq. c) that allows attackers to trigger memory corruption by supplying a crafted Dirac data unit.

The packetizer copies an input-derived data unit or fragment size into a fixed-size buffer without an upper bound check, causing a heap buffer overflow when the crafted input is packetized for RTP output.

Severity: 8.5

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed