Back

HIGH

FFmpeg: out-of-bounds read in RV60 video decoder

Published Mar 16, 2026

Description

Out-of-bounds read in FFmpeg 8.0 and 8.0.1 RV60 video decoder (libavcodec/rv60dec.c). The quantization parameter (qp) validation at line 2267 only checks the lower bound (qp < 0) but is missing upper bound validation. The qp value can reach 65 (base value 63 from 6-bit frame header + offset +2 from read_qp_offset) while the rv60_qp_to_idx array has size 64 (valid indices 0-63). This results in out-of-bounds array access at lines 1554 (decode_cbp8), 1655 (decode_cbp16), and 1419/1421 (get_c4x4_set), potentially leading to memory disclosure or crash. A previous fix in commit 61cbcaf93f added validation only for intra frames. This vulnerability affects the released versions 8.0 (released 2025-08-22) and 8.0.1 (released 2025-11-20) and is fixed in git master commit 8abeb879df which will be included in FFmpeg 8.1.

Affected products

Remediation

Red Hat statement

To exploit this issue, an attacker needs to convince a user to process a specially crafted RV60 file. Also, the only security impact of this flaw is a limited information disclosure and a denial of service. There is no memory corruption or arbitrary command execution. Due to these reasons, this vulnerability has been rated with a moderate severity.

Red Hat mitigation

To reduce the risk of exploitation, avoid processing untrusted RV60 files with FFmpeg. If FFmpeg is deployed in a way that it processes files from untrusted sources automatically, consider running the application inside a container or a restricted sandbox environment to limit the potential security impact.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Mar 16, 2026
Updated Mar 16, 2026
Reserved Jan 9, 2026
CISA Vulnrichment
Updated Mar 16, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 16, 2026
ENISA EUVD
Assigner mitre
Published Mar 16, 2026
Updated Mar 16, 2026
Exploited since n/a
EUVD-2025-208761