HIGH 8.8 NVD
CVE-2026-30754
A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative
A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting H.264/HEVC streams via RTP using a crafted input file. This was detected using AddressSanitizer.
References
- https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20746
- https://gist.github.com/momo-trip/4cddf2c9e15600873de55259dac6b0e6
- https://github.com/momo-trip/poc_ffmpeg
This high severity vulnerability with a CVSS score of 8.8 was published on 2026-09-08 via NVD.
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.