Out-of-bounds read in FFmpeg - CVE-2026-30997
Published: June 23, 2026
FFmpeg
Detailed vulnerability description
The vulnerability allows a remote attacker to crash the application.
The vulnerability exists due to a boundary condition within the read_global_param() function in libavcodec/av1dec.c. A remote attacker can create a specially crafted media content to the application, trigger an out-of-bounds read error and perform a denial of service attack.