Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with a startNumber that is lower than the previous value, the current sequence number is driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negative index to be used and causing an out-of-bounds read. A malicious or misconfigured DASH server can trigger this by serving a live manifest with a decreasing startNumber across a manifest refresh.
This is fixed in: 9.0.1: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/999f8ba75ce0bf1167677de7e11a5af678fdb866 So only F44 and older are affected.
8.1.3: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/62d4ca1f3ead52ac45c9ceae761e0139f42bfd4b
FEDORA-2026-3e109a0c85 (ffmpeg-8.1.3-1.fc44) has been submitted as an update to Fedora 44. https://bodhi.fedoraproject.org/updates/FEDORA-2026-3e109a0c85