
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-38348 is an integer overflow vulnerability in the libswscale/utils.c component of FFmpeg that allows attackers to cause a Denial of Service (DoS) by supplying a crafted image file. It affects FFmpeg version N-122528-gdd2976b9e1 and was published on August 28, 2026. The vulnerability carries a CVSS v3.1 base score of 7.5 (High), reflecting its network-exploitable, unauthenticated, and no-user-interaction attack profile (GitHub Advisory, Red Hat Bugzilla).
The root cause is an integer overflow or wraparound (CWE-190) in the libswscale/utils.c source file of FFmpeg, mapped to CAPEC-92 (Forced Integer Overflow). When FFmpeg processes a specially crafted image file, an arithmetic operation in the scaling utility code produces a value that exceeds the bounds of its integer type, leading to unexpected behavior and process crash. The attack vector is network-based with low complexity, requiring no privileges or user interaction, making it trivially automatable. The issue was reported via the FFmpeg issue tracker (FFmpeg Issue, GitHub Advisory).
Successful exploitation results in a Denial of Service, crashing or hanging the FFmpeg process when it attempts to process a malicious image file. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability. Applications and services that rely on FFmpeg for media processing (e.g., transcoding pipelines, video platforms, or image conversion services) could be disrupted if exposed to attacker-controlled input (GitHub Advisory, Red Hat Bugzilla).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and classifies the vulnerability as automatable. The EPSS score is approximately 0.149–0.324%, indicating a low but non-negligible probability of exploitation within 30 days. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
No specific patched version has been identified in the advisory at this time. Recommended mitigations include avoiding processing image files from untrusted sources with vulnerable FFmpeg versions, implementing input validation or sandboxing around FFmpeg invocations that handle user-supplied files, and monitoring the FFmpeg project for patch releases. Organizations should track the upstream FFmpeg issue tracker and apply patches promptly upon release (GitHub Advisory, Red Hat Bugzilla).
Fix availability across major Linux distributions and their releases.
bookworm
ffmpeg: 7:5.1.9-0+deb12u1
sid
ffmpeg: 7:8.1-1
trixie
ffmpeg: 7:7.1.4-0+deb13u1
bionic (esm-apps)
ffmpeg
devel
ffmpeg
focal (esm-apps)
ffmpeg
jammy
ffmpeg
jammy (esm-apps)
ffmpeg
noble
ffmpeg
noble (esm-apps)
ffmpeg
resolute
ffmpeg
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."