{"id":"CVE-2022-2566","summary":"Heap-memory write in FFMPEG","details":"A heap out-of-bounds memory write exists in FFMPEG since version 5.1. The size calculation in `build_open_gop_key_points()` goes through all entries in the loop and adds `sc-\u003ectts_data[i].count` to `sc-\u003esample_offsets_count`. This can lead to an integer overflow resulting in a small allocation with `av_calloc()`. An attacker can cause remote code execution via a malicious mp4 file. We recommend upgrading past commit c953baa084607dd1d84c3bfcce3cf6a87c3e6e05","modified":"2026-08-17T05:26:17.443085Z","published":"2022-09-23T11:10:14.367Z","related":["openSUSE-SU-2024:12332-1"],"database_specific":{"cna_assigner":"Google","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2566.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"ab77b878f1205225c6de1370fb0e998dbcc8bc69"},{"last_affected":"ab77b878f1205225c6de1370fb0e998dbcc8bc69"},{"fixed":"c953baa084607dd1d84c3bfcce3cf6a87c3e6e05"}]}]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/2xxx/CVE-2022-2566.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-2566"},{"type":"FIX","url":"https://github.com/FFmpeg/FFmpeg/commit/c953baa084607dd1d84c3bfcce3cf6a87c3e6e05"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.ffmpeg.org/ffmpeg.git","events":[{"introduced":"b189550137155a622f88df6e64e72c2cca660854"},{"last_affected":"b189550137155a622f88df6e64e72c2cca660854"}],"database_specific":{"cpe":"cpe:2.3:a:ffmpeg:ffmpeg:5.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"5.1"},{"last_affected":"5.1"}],"source":"CPE_STRING"}},{"type":"GIT","repo":"https://github.com/ffmpeg/ffmpeg","events":[{"introduced":"b189550137155a622f88df6e64e72c2cca660854"},{"fixed":"c953baa084607dd1d84c3bfcce3cf6a87c3e6e05"}],"database_specific":{"extracted_events":[{"introduced":"5.1"},{"last_affected":"5.1"}],"source":["CPE_STRING","REFERENCES"],"cpe":"cpe:2.3:a:ffmpeg:ffmpeg:5.1:*:*:*:*:*:*:*"}}],"versions":["5.1","n5.1-dev","n5.2-dev"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-2566.json","vanir_signatures_modified":"2026-08-17T05:26:17Z","vanir_signatures":[{"source":"https://github.com/ffmpeg/ffmpeg/commit/c953baa084607dd1d84c3bfcce3cf6a87c3e6e05","target":{"file":"libavformat/mov.c"},"deprecated":false,"digest":{"line_hashes":["229648891667041450029361493606381806304","135872466468465938462320271973817091921","210085637948337441042887757423541642970","86198498164871402896199974580337423354","121449979526773324259872295402571671113","50255533385114424664651841403325448377","32389276260174103705251316886652202128","319058207834156408004807609848915542153","150489999679500154117254249613797223827","280751541028273460609967900500999004211","7058286243398018117911243721609085803","212616978249885233513896020834881085416","309461606343329441956372708679658228926","16390099522419099115180149235540250455"],"threshold":0.9},"id":"CVE-2022-2566-64df0c29","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/ffmpeg/ffmpeg/commit/c953baa084607dd1d84c3bfcce3cf6a87c3e6e05","target":{"function":"build_open_gop_key_points","file":"libavformat/mov.c"},"deprecated":false,"digest":{"function_hash":"143989625785103494375096093135229489196","length":1772},"id":"CVE-2022-2566-ffc21973"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}