FFmpeg Stack Buffer Overflow in MPEG-PS Muxer via mpegenc.c
Published Aug 19, 2026
8.5
HIGHCVSS 4.0
EPSS 0.20%
Description
FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.
Affected products
-
Affected
- ≥ 0, <
No data.
No data.
Red Hat Enterprise Linux AI (RHEL AI) 3
ffmpeg
Fix deferred
Red Hat OpenShift AI (RHOAI)
rhoai/odh-vllm-gaudi-rhel9
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux AI (RHEL AI) 3 | ffmpeg | Fix deferred | n/a |
| Red Hat OpenShift AI (RHOAI) | rhoai/odh-vllm-gaudi-rhel9 | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The ffmpeg package is not shipped in base Red Hat Enterprise Linux. It is available through EPEL, Red Hat Enterprise Linux AI, and as a bundled dependency in Red Hat OpenShift AI container images. The vulnerable code resides in the MPEG-PS muxer (libavformat/mpegenc.c), which is compiled and shipped in all FFmpeg builds across these products. This is a stack buffer overflow triggered by input with an excessive number of streams.
Red Hat mitigation
No mitigation is currently available for this flaw.
References (8)
- https://access.redhat.com/security/cve/CVE-2026-75142 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2519759 Issue Tracking
- https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9d786e4b5e9b8482651928574de33772aeee7be1 patch
- https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24087 issue-tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-62579 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-75142
- https://www.cve.org/CVERecord?id=CVE-2026-75142
- https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-mpeg-ps-muxer-via-mpegenc-c third-party-advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub
No data