{"id":"CVE-2026-75146","summary":"FFmpeg Out-of-Bounds Read in DASH Demuxer via dashdec.c","details":"FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.","modified":"2026-10-08T07:39:16.220996547Z","published":"2026-08-19T16:28:19.356Z","related":["SUSE-SU-2026:4149-1","SUSE-SU-2026:4150-1","openSUSE-SU-2026:11659-1","openSUSE-SU-2026:11665-1","openSUSE-SU-2026:11682-1","openSUSE-SU-2026:11716-1","openSUSE-SU-2026:21877-1"],"database_specific":{"cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75146.json","cna_assigner":"VulnCheck"},"references":[{"type":"WEB","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75146.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75146"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-in-dash-demuxer-via-dashdec-c"},{"type":"REPORT","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24093"},{"type":"FIX","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/65b0dab903e5975e036b30ecc58f5935d4f151e0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://code.ffmpeg.org/FFmpeg/FFmpeg","events":[{"introduced":"0"},{"fixed":"65b0dab903e5975e036b30ecc58f5935d4f151e0"}]}],"versions":["n9.1-dev","n8.2-dev","n8.1-dev","n7.2-dev","n7.1-dev","n6.2-dev","n6.1-dev","n5.2-dev","n5.1-dev","n4.5-dev","n4.4-dev","n4.3-dev","n4.2-dev","n4.1-dev","n3.5-dev","n3.4-dev","n3.3-dev","n3.2-dev","n3.1-dev","n2.9-dev","n2.8-dev","n2.7-dev","n2.6-dev","n2.5-dev","n2.4-dev","n2.3-dev","n2.2-dev","n2.0","n2.1-dev","n1.3-dev","n1.2-dev","n1.1-dev","n0.12-dev","n0.11-dev","n0.8","N"],"database_specific":{"vanir_signatures":[{"target":{"function":"move_segments","file":"libavformat/dashdec.c"},"deprecated":false,"digest":{"function_hash":"307570546108117083969007297720946930034","length":535},"id":"CVE-2026-75146-08570d35","signature_type":"Function","signature_version":"v1","source":"https://code.ffmpeg.org/FFmpeg/FFmpeg@65b0dab903e5975e036b30ecc58f5935d4f151e0"},{"signature_version":"v1","source":"https://code.ffmpeg.org/FFmpeg/FFmpeg@65b0dab903e5975e036b30ecc58f5935d4f151e0","target":{"file":"libavformat/dashdec.c"},"deprecated":false,"digest":{"line_hashes":["312369478147089745414888542726523281367","50427058296031127192295708817577645574","43175266050272866375146862736790901369","326112046778768842598715146398635712251","125553747509471924331829218456209593164","248606786996328159755046163842587150965","11117762287937624563618178153849021753","48139934443569739143388270718883943515","110238175479310822534449300345287680574"],"threshold":0.9},"id":"CVE-2026-75146-68124e6e","signature_type":"Line"},{"id":"CVE-2026-75146-89ad98a9","signature_type":"Function","signature_version":"v1","source":"https://code.ffmpeg.org/FFmpeg/FFmpeg@65b0dab903e5975e036b30ecc58f5935d4f151e0","target":{"file":"libavformat/dashdec.c","function":"get_current_fragment"},"deprecated":false,"digest":{"length":2641,"function_hash":"333738960995188443878179064075476379321"}}],"vanir_signatures_modified":"2026-10-08T07:39:16Z","source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75146.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N"}]}