CVE-2024-7272General(ffmpeg / ffmpeg)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability, which was classified as critical, was found in FFmpeg up to 5.1.5. This affects the function fill_audiodata of the file /libswresample/swresample.c. The manipulation leads to heap-based buffer overflow. It is possible to initiate the attack remotely. This issue was fixed in version 6.0 by 9903ba28c28ab18dc7b7b6fb8571cc8b5caae1a6 but a backport for 5.1 was forgotten. The exploit has been disclosed to the public and may be used. Upgrading to version 5.1.6 and 6.0 9903ba28c28ab18dc7b7b6fb8571cc8b5caae1a6 is able to address this issue. It is recommended to upgrade the affected component.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ffmpeg

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ffmpeg

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-03-17: 1Technical Details · 2026-03-17: 103-17
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • Hope@Hopeq7d2
    General

    In some security contexts like CVE-2023-7272 or CVE-2024-7272, these are vulnerability IDs (e.g., stack overflow in JSON parsers or heap buffer overflow in FFmpeg), which could cause app crashes if exploited, but they’re not “code 7272 crash” phrased that way.

    Post summary

    The passage identifies CVE-2023-7272 and CVE-2024-7272 as causing stack and heap overflows that can crash applications, without additional exploitation or mitigation details.

    00000105
    117 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appffmpegffmpeg---

Explore more