CVE-2026-107678 — FFmpeg through 9.0.2 contains a stack exhaustion vulnerability in av_encryption_init_info_free() in libavutil/encryption_info.c, which recursively …
Description
FFmpeg through 9.0.2 contains a stack exhaustion vulnerability in av_encryption_init_info_free() in libavutil/encryption_info.c, which recursively frees AVEncryptionInitInfo linked lists built by the MOV demuxer's mov_read_pssh(). Attackers can supply a crafted MP4 file with tens of thousands of small pssh boxes to exhaust the stack and crash the process, while also causing quadratic CPU consumption.
CVSS v4.0 base metrics
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Local
Attack Vector
AC
High
Attack Complexity
AT
Present
Attack Requirements
PR
None
Privileges Required
UI
Passive
User Interaction
VC
None
Confidentiality (Vulnerable System)
VI
None
Integrity (Vulnerable System)
VA
High
Availability (Vulnerable System)
SC
None
Confidentiality (Subsequent System)
SI
None
Integrity (Subsequent System)
SA
None
Availability (Subsequent System)
References
- advisory[email protected]https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24593
- advisory[email protected]https://ffmpeg.org/
- advisory[email protected]https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavformat/mov.c#L8070
- advisory[email protected]https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavutil/encryption_info.c#L219-L231
- advisory[email protected]https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-stack-exhaustion-via-recursive-free-of-pssh-boxes
Related threats
same CWE or vendorCVE-2026-19498 — IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 could allow a remote attacker to cause a denial…
CVE-2026-19498 · 3h ago
CVE-2026-107376 — webonyx graphql-php is a PHP implementation of the GraphQL specification.
CVE-2026-107376 · 6h ago
Coraza: Unbounded recursion in JSON response body processor causes CPU exhaustion
OSV · 7h ago
Coraza JSON body processor: argument-limit truncation reopens an unbounded-depth gjson.Valid stack overflow (process crash)
OSV · 7h ago
CVE-2026-107300 — msgpack5 is a msgpack v5 implementation for node.js and the browser.
CVE-2026-107300 · 7h ago
CVE-2026-107298 — msgpack5 is a msgpack v5 implementation for node.js and the browser.
CVE-2026-107298 · 7h ago