
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-38349 is an integer overflow vulnerability in FFmpeg's hScale16To19_c() function located in libswscale/output.c, which allows unauthenticated attackers to cause a Denial of Service (DoS) by supplying a crafted image file. The vulnerability affects FFmpeg version N-122528-gdd2976b9e1; exact patched version details are not yet listed in the advisory. It was published on August 28, 2026, with the GitHub Advisory Database and Red Hat Bugzilla tracking it concurrently. The CVSS v3.1 base score is 7.5 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is an integer overflow or wraparound (CWE-190) in the hScale16To19_c() function within FFmpeg's libswscale/output.c, which handles image scaling operations. When processing a specially crafted image file, the function performs a calculation that overflows the integer representation, leading to an unexpected value that causes the process to crash. The attack vector is network-based, requires no authentication or user interaction, and has low attack complexity, making it automatable. The upstream issue is tracked at the FFmpeg issue tracker (GitHub Advisory, FFmpeg Issue).
Successful exploitation results in a crash of the FFmpeg process, causing a Denial of Service with high availability impact. There is no confidentiality or integrity impact — attackers cannot read data or modify system state through this vulnerability. Any service or application that relies on FFmpeg for image or media processing (e.g., transcoding pipelines, media servers, web applications) could be disrupted by an attacker submitting a malicious image file (GitHub Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The NVD SSVC assessment classifies exploitation as "none" and the attack as automatable with partial technical impact. The EPSS score is approximately 0.149%, indicating a low near-term probability of exploitation. CVE-2026-38349 is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
hScale16To19_c() scaling function during processing.hScale16To19_c() within libswscale/output.c, causing the process to crash and resulting in a Denial of Service for the affected service (GitHub Advisory, FFmpeg Issue).dmesg, syslog, application error logs) correlated with image processing requests.Update FFmpeg to a version that includes a fix for the integer overflow in hScale16To19_c(); monitor the official FFmpeg release notes and the upstream issue tracker for patch availability (FFmpeg Issue, GitHub Advisory). As interim mitigations, validate and sanitize image inputs before passing them to FFmpeg, enforce file size and format restrictions, and implement resource limits (e.g., process timeouts, memory caps) to reduce the impact of crashes. Monitor FFmpeg processes for unexpected termination and consider running FFmpeg in an isolated environment (e.g., container or sandbox) to limit blast radius.
Red Hat has opened a high-severity bug tracking this CVE (Bug 2525327) and assigned it to their Product Security DevOps Team, indicating active vendor awareness (Red Hat Bugzilla). The GitHub Advisory Database has published the advisory as "Unreviewed" with High severity. No notable researcher commentary or significant social media discussion has been identified at this time.
Fix availability across major Linux distributions and their releases.
bookworm
ffmpeg: 7:5.1.9-0+deb12u1
sid
ffmpeg: 7:8.1-1
trixie
ffmpeg: 7:7.1.4-0+deb13u1
bionic (esm-apps)
ffmpeg
devel
ffmpeg
focal (esm-apps)
ffmpeg
jammy
ffmpeg
jammy (esm-apps)
ffmpeg
noble
ffmpeg
noble (esm-apps)
ffmpeg
resolute
ffmpeg
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."