Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-66037— FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()

CVSS 6.5 · Medium EPSS 0.28% · P20

Possible ATT&CK Techniques 1AI

T1496 · Resource Hijacking

Affected Version Matrix 2

VendorProductVersion RangeStatus
FFmpegFFmpeg≤ 8.1.2affected
86708357d126af84c16f80d9c57335d1e8c845c5unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-66037

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FFmpeg IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu()
Source: CVE Program / CVE List V5
Vulnerability Description
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled value before validating available OBU data, enabling an allocation amplification of approximately 126 million bytes per input byte that exhausts process memory or triggers an OOM-kill during format probing.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
不加限制或调节的资源分配
Source: CVE Program / CVE List V5

Affected Products

VendorProductAffected VersionsCPESubscribe
FFmpegFFmpeg 0 ~ 8.1.2 -

II. Public POCs for CVE-2026-66037

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-66037

登录查看更多情报信息。

Patches & Fixes for CVE-2026-66037 (2)

Vendor Advisories for CVE-2026-66037 (1)

Same Patch Batch · FFmpeg · 2026-07-24 · 6 CVEs total

CVE-2026-660368.8 HIGHFFmpeg Heap Out-of-Bounds Write in vf_hqdn3d Filter
CVE-2026-660408.8 HIGHFFmpeg Heap Out-of-Bounds Write via PNG/APNG eXIf Encoder
CVE-2026-660418.8 HIGHFFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter
CVE-2026-660398.8 HIGHFFmpeg MACE6 Audio Decoder Heap Out-of-Bounds Write via CAF File
CVE-2026-660386.5 MEDIUMFFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c

IV. Related Vulnerabilities

V. Comments for CVE-2026-66037

No comments yet


Leave a comment