CVE-2026-75143Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied the full received payload length into the caller-provided destination buffer, overflowing it when the payload exceeds the destination size. This is reachable via the async:rist:// URL scheme, where the async wrapper supplies a smaller buffer than the received payload. A remote RIST sender can trigger the overflow by sending a packet whose payload exceeds the caller buffer size.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-08-19); latest day: 1
  • 4 total mentions across 3 days

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-08-19: 2Mentions · 2026-08-20: 1Mentions · 2026-08-23: 1Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-23: 1Technical Details · 2026-08-19: 2Technical Details · 2026-08-20: 1Technical Details · 2026-08-23: 108-1908-2008-23
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-192
Disclosure2
2026-08-201
Disclosure1
2026-08-231
Patch1
Full discourse4 posts
  • David Chen@amtecco
    Patch

    CVE-2026-75143: heap overflow in FFmpeg's RIST reader. CVSS 9.3. librist_read() ignored its size argument. Over async:rist:// the wrapper hands it a smaller buffer than the payload, so a remote sender can overflow it. Not a RIST protocol flaw. An FFmpeg one. Fixed in 1c10bcc.

    Post summary

    The post reports a severe heap overflow in FFmpeg’s RIST reader, details the technical exploitation scenario, and notes the fix in commit 1c10bcc, with no evidence of current exploitation or PoC.

    0000057
    26 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨Critical - FFmpeg RIST protocol reader heap overflow (CVE-2026-75143) librist_read() in libavformat/librist.c ignores its size argument and copies the full received payload into the caller's buffer, overflowing it. Reachable via async:rist://, where the async wrapper supplies a smaller buffer than the payload — a remote RIST sender triggers it with one oversized packet, no auth, no interaction. Only affects librist-enabled builds ingesting RIST streams. 👉Affected: FFmpeg before commit 1c10bcc | Upgrade to a build including 1c10bcc · CVSS 9.8 · no fixed release yet

    Post summary

    FFmpeg CVE‑2026‑75143 is a critical RIST protocol heap overflow with a CVSS score of 9.8. It is mitigated by upgrading to a build that includes commit 1c10bcc, though no fixed release is yet available.

    0000067
    292 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-75143 FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied … https://www.cve.org/CVERecord?id=CVE-2026-75143 ----- Traducción: CVE-2026-75143 FFm… https://infoflow.cloud`

    Post summary

    The post announces a heap buffer overflow CVE‑2026‑75143 in FFmpeg’s RIST protocol reader, providing technical details but no PoC, patch, or evidence of active exploitation.

    0000027
    100 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-75143 FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size argument and copied … https://www.cve.org/CVERecord?id=CVE-2026-75143

    Post summary

    The post reports a newly disclosed heap buffer overflow in FFmpeg’s RIST protocol reader, providing technical details but no PoC, exploit, or mitigation information.

    000001.1K
    58.0K followersView on X

Explore more