Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-38348
Ffmpeg vulnerability analysis and mitigation

Overview

CVE-2026-38348 is an integer overflow vulnerability in the libswscale/utils.c component of FFmpeg that allows attackers to cause a Denial of Service (DoS) by supplying a crafted image file. It affects FFmpeg version N-122528-gdd2976b9e1 and was published on August 28, 2026. The vulnerability carries a CVSS v3.1 base score of 7.5 (High), reflecting its network-exploitable, unauthenticated, and no-user-interaction attack profile (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is an integer overflow or wraparound (CWE-190) in the libswscale/utils.c source file of FFmpeg, mapped to CAPEC-92 (Forced Integer Overflow). When FFmpeg processes a specially crafted image file, an arithmetic operation in the scaling utility code produces a value that exceeds the bounds of its integer type, leading to unexpected behavior and process crash. The attack vector is network-based with low complexity, requiring no privileges or user interaction, making it trivially automatable. The issue was reported via the FFmpeg issue tracker (FFmpeg Issue, GitHub Advisory).

Impact

Successful exploitation results in a Denial of Service, crashing or hanging the FFmpeg process when it attempts to process a malicious image file. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability. Applications and services that rely on FFmpeg for media processing (e.g., transcoding pipelines, video platforms, or image conversion services) could be disrupted if exposed to attacker-controlled input (GitHub Advisory, Red Hat Bugzilla).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and classifies the vulnerability as automatable. The EPSS score is approximately 0.149–0.324%, indicating a low but non-negligible probability of exploitation within 30 days. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Mitigation and workarounds

No specific patched version has been identified in the advisory at this time. Recommended mitigations include avoiding processing image files from untrusted sources with vulnerable FFmpeg versions, implementing input validation or sandboxing around FFmpeg invocations that handle user-supplied files, and monitoring the FFmpeg project for patch releases. Organizations should track the upstream FFmpeg issue tracker and apply patches promptly upon release (GitHub Advisory, Red Hat Bugzilla).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

ffmpeg: 7:5.1.9-0+deb12u1

Fixed

sid

ffmpeg: 7:8.1-1

Fixed

trixie

ffmpeg: 7:7.1.4-0+deb13u1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

ffmpeg

Unknown

devel

ffmpeg

Unknown

focal (esm-apps)

ffmpeg

Unknown

jammy

ffmpeg

Unknown

jammy (esm-apps)

ffmpeg

Unknown

noble

ffmpeg

Unknown

noble (esm-apps)

ffmpeg

Unknown

resolute

ffmpeg

Unknown

RHEL / CentOS

Unknown

SourceThis report was generated using AI

Related Ffmpeg vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-30754HIGH8.8
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 08, 2026
CVE-2026-90816MEDIUM5.3
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 14, 2026
CVE-2026-52297LOW2.9
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 13, 2026
CVE-2026-52296LOW2.9
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 13, 2026
CVE-2026-90815LOW2.1
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management