HIGHVulnerability

CVE-2026-75141

FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of a single type than the count field can represent, the NAL unit count overflows, causing a heap buffer overflow. A crafted HEVC input file triggers the overflow during muxing.

Properties

severity
HIGH
score
7.8
epss_score
0.00137
cve_id
CVE-2026-75141
vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
published_at
2026-08-19T17:21:12.287
last_modified
2026-08-31T20:37:35.877
epss_percentile
0.03418

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Heap-based Buffer Overflow

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-75141 — Ninja Signal Threat Intelligence | Ninja Signal