Back

HIGH

FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c

Published Aug 19, 2026

Description

FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.

Affected products

Remediation

Red Hat statement

The ffmpeg package is not shipped in base Red Hat Enterprise Linux. It is available through EPEL, Red Hat Enterprise Linux AI, and as a bundled dependency in Red Hat OpenShift AI container images. The vulnerable code resides in the MPEG-PS muxer (libavformat/mpegenc.c), which is compiled and shipped in all FFmpeg builds across these products. This is a stack buffer overflow triggered by input with an excessive number of streams.

Red Hat mitigation

No mitigation is currently available for this flaw.

References (8)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulnCheck
Published Aug 19, 2026
Updated Aug 27, 2026
Reserved Aug 17, 2026

CISA Vulnrichment

Updated Aug 21, 2026

NVD

Status Awaiting Analysis
Modified Sep 9, 2026

Red Hat

Severity Important
Public date Aug 19, 2026
Bugzilla 2519759

ENISA EUVD

Assigner VulnCheck
Published Aug 19, 2026
Updated Aug 27, 2026

GitHub

No data