CVE-2024-31582
Ffmpeg vulnerability analysis and mitigation

Overview

FFmpeg version n6.1 contains a heap buffer overflow vulnerability in the draw_block_rectangle function located in libavfilter/vf_codecview.c. The vulnerability was discovered and disclosed on April 17, 2024 (NVD).

Technical details

The vulnerability exists in the draw_block_rectangle function of libavfilter/vf_codecview.c and has been assigned a CVSS v3.1 base score of 7.8 HIGH (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). The issue is classified as a CWE-122: Heap-based Buffer Overflow vulnerability (NVD).

Impact

When exploited, this vulnerability allows attackers to cause undefined behavior or a Denial of Service (DoS) through crafted input. The high CVSS score indicates potential severe impacts on system confidentiality, integrity, and availability (NVD).

Exploitability

The vulnerability can be triggered via crafted input that targets the draw_block_rectangle function. The attack requires local access and user interaction, as indicated by the CVSS metrics (NVD).

Mitigation and workarounds

A fix has been implemented and is available in the FFmpeg commit 99debe5f823f45a482e1dc08de35879aa9c74bd2. Ubuntu has released fixes for affected versions in Ubuntu 23.10 (version 7:6.0-6ubuntu1.1) and Ubuntu 24.04 LTS (version 7:6.1.1-3ubuntu5+esm1) (Ubuntu).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

ffmpeg: 7:5.1.7-0+deb12u1

Fixed

bullseye

ffmpeg

Fixed

sid

ffmpeg: 7:7.0.1-3

Fixed

trixie

ffmpeg: 7:7.0.1-3

Fixed

SourceThis report was generated using AI

Related Ffmpeg vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-30754HIGH8.8
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 08, 2026
CVE-2026-90816MEDIUM5.3
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 14, 2026
CVE-2026-52297LOW2.9
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 13, 2026
CVE-2026-52296LOW2.9
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 13, 2026
CVE-2026-90815LOW2.1
  • Ffmpeg logoFfmpeg
  • cpe:2.3:a:ffmpeg:ffmpeg
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management