{"id":"CVE-2026-70629","summary":"FFmpeg 3.0 \u003c 9.0 Uninitialized Heap Memory Read in RSCC Decoder","details":"FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx-\u003einflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services.","modified":"2026-09-03T10:10:55.121996412Z","published":"2026-08-06T21:25:08.804Z","related":["openSUSE-SU-2026:11659-1","openSUSE-SU-2026:11665-1"],"database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-908"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70629.json","unresolved_ranges":[{"extracted_events":[{"introduced":"3.0"},{"fixed":"9.0"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"introduced":"3.0"},{"fixed":"9.0"}],"source":"CPE_FIELD"}]},"references":[{"type":"WEB","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg"},{"type":"WEB","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70629.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70629"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ffmpeg-uninitialized-heap-memory-read-in-rscc-decoder"},{"type":"REPORT","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895"},{"type":"FIX","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4"},{"type":"FIX","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.ffmpeg.org/ffmpeg.git","events":[{"introduced":"c40983a6f631d22fede713d535bb9c31d5c9740c"},{"fixed":"d32b387f2b0a484599d4587d651891f0c63c4238"}],"database_specific":{"cpe":"cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.0"},{"fixed":"9"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70629.json","vanir_signatures_modified":"2026-09-03T08:03:53Z","vanir_signatures":[{"id":"CVE-2026-70629-bded55e5","signature_type":"Line","signature_version":"v1","source":"https://git.ffmpeg.org/ffmpeg.git@d32b387f2b0a484599d4587d651891f0c63c4238","target":{"file":"libavformat/rawutils.c"},"deprecated":false,"digest":{"line_hashes":["195688002327067465305765588221319015242","309288324102816931239308632619998175099","208198982209572275918917816535860937592","231555107084919634110330250551123341431","168010716807985158773806969924424380093","204275076296265396432751791373547480918","230743041424433407137898346131591666852","121645463046297428931382762675379161144","64606519716965107927271010747911179138","73767112427060832523002513151109600034","219167262246002076747638059747044171272"],"threshold":0.9}},{"digest":{"function_hash":"95585342688571589449512382820310933372","length":1096},"id":"CVE-2026-70629-bfd07778","signature_type":"Function","signature_version":"v1","source":"https://git.ffmpeg.org/ffmpeg.git@d32b387f2b0a484599d4587d651891f0c63c4238","target":{"file":"libavformat/rawutils.c","function":"ff_reshuffle_raw_rgb"},"deprecated":false}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/ffmpeg/ffmpeg","events":[{"introduced":"c40983a6f631d22fede713d535bb9c31d5c9740c"},{"fixed":"d32b387f2b0a484599d4587d651891f0c63c4238"}],"database_specific":{"cpe":"cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.0"},{"fixed":"9"}],"source":"CPE_RANGE"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70629.json","vanir_signatures_modified":"2026-09-03T08:03:53Z","vanir_signatures":[{"target":{"file":"libavformat/rawutils.c","function":"ff_reshuffle_raw_rgb"},"deprecated":false,"digest":{"function_hash":"95585342688571589449512382820310933372","length":1096},"id":"CVE-2026-70629-2a07b12d","signature_type":"Function","signature_version":"v1","source":"https://github.com/ffmpeg/ffmpeg/commit/d32b387f2b0a484599d4587d651891f0c63c4238"},{"source":"https://github.com/ffmpeg/ffmpeg/commit/d32b387f2b0a484599d4587d651891f0c63c4238","target":{"file":"libavformat/rawutils.c"},"deprecated":false,"digest":{"line_hashes":["195688002327067465305765588221319015242","309288324102816931239308632619998175099","208198982209572275918917816535860937592","231555107084919634110330250551123341431","168010716807985158773806969924424380093","204275076296265396432751791373547480918","230743041424433407137898346131591666852","121645463046297428931382762675379161144","64606519716965107927271010747911179138","73767112427060832523002513151109600034","219167262246002076747638059747044171272"],"threshold":0.9},"id":"CVE-2026-70629-5f4309c9","signature_type":"Line","signature_version":"v1"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}