Back

HIGH

FFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder

Published Jul 24, 2026

Description

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 24, 2026
Updated Jul 29, 2026
Reserved Jul 23, 2026
CISA Vulnrichment
Updated Jul 27, 2026
NVD
Status Analyzed
Modified Aug 7, 2026
Red Hat
Severity Important
Public date Jul 24, 2026
ENISA EUVD
Assigner VulnCheck
Published Jul 24, 2026
Updated Jul 29, 2026
Exploited since n/a
EUVD-2026-48742