Skip to finding
important · Zero-click / RCE

A malformed VVC bitstream can write past FFmpeg's slice-entry-point array.

Affects

FFmpeg, a cross-platform multimedia decoding and processing library used by media applications and services.

An affected consumer must decode the bitstream; missing entry-point bounds enforcement then produces an out-of-bounds CTU-index write.

Detail and 3 sources

Code-execution control and an automatic remote delivery path remain unproved. The fix reached master and release/9.0, but it was not read for a Priority Finding.

Chain to watch
Deliver a crafted VVC bitstream to an affected consumer→↓Trigger the slice-entry-point overwrite→↓Establish overwrite control and an automatic remote ingestion path→↓Both exploitability and receipt-only reachability remain unproved.
Unverified chainReproduce the regression input, characterize the overwritten object and test automatic VVC consumers.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 19, 2026