CVE-2026-107678
FFmpeg through 9.0.2 Stack Exhaustion via Recursive Free of pssh Boxes
CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th
FFmpeg through 9.0.2 contains a stack exhaustion vulnerability in av_encryption_init_info_free() in libavutil/encryption_info.c, which recursively frees AVEncryptionInitInfo linked lists built by the MOV demuxer's mov_read_pssh(). Attackers can supply a crafted MP4 file with tens of thousands of small pssh boxes to exhaust the stack and crash the process, while also causing quadratic CPU consumption.
| CWE | CWE-674 |
| Vendor | ffmpeg |
| Product | ffmpeg |
| Published | Oct 8, 2026 |
| Last Updated | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for ffmpeg ffmpeg
Be the first to know when new medium vulnerabilities affecting ffmpeg ffmpeg are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
FFmpeg / FFmpeg
0 โค 9.0.2
References
code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24593 github.com: https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavutil/encryption_info.c#L219-L231 github.com: https://github.com/FFmpeg/FFmpeg/blob/n9.0.2/libavformat/mov.c#L8070 ffmpeg.org: https://ffmpeg.org/ vulncheck.com: https://www.vulncheck.com/advisories/ffmpeg-through-9.0.2-stack-exhaustion-via-recursive-free-of-pssh-boxes
Credits
Joshua Rogers (AISLE Research)