CVE-2026-30999

unknown
EUVD alias: EUVD-2026-21976
Published 2026-09-14 · Modified —
CVSS v3
CVSS v4 NEW
not yet in upstream
VIR risk

Description

FFmpeg vulnerabilities

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-30999 NameCVE-2026-30999 DescriptionA heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table…

CVE-2026-30999

NameCVE-2026-30999
DescriptionA heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
ffmpeg (PTS)bullseye7:4.3.7-0+deb11u1vulnerable
bullseye (security)7:4.3.9-0+deb11u2vulnerable
bookworm7:5.1.8-0+deb12u1vulnerable
bookworm (security)7:5.1.9-0+deb12u1vulnerable
trixie7:7.1.3-0+deb13u1vulnerable
trixie (security)7:7.1.5-0+deb13u1vulnerable
forky, sid7:8.1.2-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
ffmpegsource(unstable)7:8.1.2-1unimportant

Notes

https://github.com/ffmpeg/fFmpeg/commit/144af8f81abc1385631b4e1f4672cd415a9c6e05
No security impact, memory leak in CLI tool

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
https://github.com/ffmpeg/fFmpeg/commit/144af8f81abc1385631b4e1f4672cd415a9c6e05No security impact, memory leak in CLI tool

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
Affected
debian Debian Mixed 5 releases
VersionStatusFixed in
trixie Affected
sid Fixed 7:8.1.2-1
forky Fixed 7:8.1.2-1
bullseye Affected
bookworm Affected
ubuntu Ubuntu Fixed 2 releases
VersionStatusFixed in
jammy Fixed 7:4.4.2-0ubuntu0.22.04.1+esm16
focal Fixed 7:4.2.7-0ubuntu0.1+esm17

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.