Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-38349
Ffmpeg vulnerability analysis and mitigation

Overview

CVE-2026-38349 is an integer overflow vulnerability in FFmpeg's hScale16To19_c() function located in libswscale/output.c, which allows unauthenticated attackers to cause a Denial of Service (DoS) by supplying a crafted image file. The vulnerability affects FFmpeg version N-122528-gdd2976b9e1; exact patched version details are not yet listed in the advisory. It was published on August 28, 2026, with the GitHub Advisory Database and Red Hat Bugzilla tracking it concurrently. The CVSS v3.1 base score is 7.5 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is an integer overflow or wraparound (CWE-190) in the hScale16To19_c() function within FFmpeg's libswscale/output.c, which handles image scaling operations. When processing a specially crafted image file, the function performs a calculation that overflows the integer representation, leading to an unexpected value that causes the process to crash. The attack vector is network-based, requires no authentication or user interaction, and has low attack complexity, making it automatable. The upstream issue is tracked at the FFmpeg issue tracker (GitHub Advisory, FFmpeg Issue).

Impact

Successful exploitation results in a crash of the FFmpeg process, causing a Denial of Service with high availability impact. There is no confidentiality or integrity impact — attackers cannot read data or modify system state through this vulnerability. Any service or application that relies on FFmpeg for image or media processing (e.g., transcoding pipelines, media servers, web applications) could be disrupted by an attacker submitting a malicious image file (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as automatable with partial technical impact. The EPSS score is approximately 0.149%, indicating a low near-term probability of exploitation. CVE-2026-38349 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify services or applications that use FFmpeg for image processing (e.g., media transcoding APIs, video platforms, image conversion services) running the affected version N-122528-gdd2976b9e1.
  2. Craft malicious image: Create a specially crafted image file with dimensions or pixel data designed to trigger an integer overflow in the hScale16To19_c() scaling function during processing.
  3. Submit crafted file: Deliver the malicious image to the target application via any input channel that passes the file to FFmpeg for processing (e.g., file upload endpoint, streaming URL, API call).
  4. Trigger DoS: FFmpeg processes the image, the integer overflow occurs in hScale16To19_c() within libswscale/output.c, causing the process to crash and resulting in a Denial of Service for the affected service (GitHub Advisory, FFmpeg Issue).

Indicators of compromise

  • Logs: Unexpected FFmpeg process crashes or segmentation fault entries in system logs (e.g., dmesg, syslog, application error logs) correlated with image processing requests.
  • Process: Repeated abnormal termination of FFmpeg worker processes, especially during image scaling operations.
  • Network: Unusual or repeated submission of image files (particularly with atypical dimensions or formats) to services that invoke FFmpeg for processing.
  • File System: Presence of malformed or oversized image files in upload directories or temporary processing folders that do not conform to standard image specifications.

Mitigation and workarounds

Update FFmpeg to a version that includes a fix for the integer overflow in hScale16To19_c(); monitor the official FFmpeg release notes and the upstream issue tracker for patch availability (FFmpeg Issue, GitHub Advisory). As interim mitigations, validate and sanitize image inputs before passing them to FFmpeg, enforce file size and format restrictions, and implement resource limits (e.g., process timeouts, memory caps) to reduce the impact of crashes. Monitor FFmpeg processes for unexpected termination and consider running FFmpeg in an isolated environment (e.g., container or sandbox) to limit blast radius.

Community reactions

Red Hat has opened a high-severity bug tracking this CVE (Bug 2525327) and assigned it to their Product Security DevOps Team, indicating active vendor awareness (Red Hat Bugzilla). The GitHub Advisory Database has published the advisory as "Unreviewed" with High severity. No notable researcher commentary or significant social media discussion has been identified at this time.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

ffmpeg: 7:5.1.9-0+deb12u1

Fixed

sid

ffmpeg: 7:8.1-1

Fixed

trixie

ffmpeg: 7:7.1.4-0+deb13u1

Fixed

Ubuntu

Unknown

bionic (esm-apps)

ffmpeg

Unknown

devel

ffmpeg

Unknown

focal (esm-apps)

ffmpeg

Unknown

jammy

ffmpeg

Unknown

jammy (esm-apps)

ffmpeg

Unknown

noble

ffmpeg

Unknown

noble (esm-apps)

ffmpeg

Unknown

resolute

ffmpeg

Unknown

RHEL / CentOS

Unknown

SourceThis report was generated using AI

Related Ffmpeg vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-30754HIGH8.8
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 08, 2026
CVE-2026-90816MEDIUM5.3
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 14, 2026
CVE-2026-52297LOW2.9
  • Ffmpeg logoFfmpeg
  • cpe:2.3:a:ffmpeg:ffmpeg
NoYesSep 13, 2026
CVE-2026-52296LOW2.9
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 13, 2026
CVE-2026-90815LOW2.1
  • Ffmpeg logoFfmpeg
  • ffmpeg
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management