
CVE-2026-75143: heap overflow in FFmpeg's RIST reader. CVSS 9.3. librist_read() ignored its size argument. Over async:rist:// the wrapper hands it a smaller buffer than the payload, so a remote sender can overflow it. Not a RIST protocol flaw. An FFmpeg one. Fixed in 1c10bcc.
Post summary
The post reports a severe heap overflow in FFmpeg’s RIST reader, details the technical exploitation scenario, and notes the fix in commit 1c10bcc, with no evidence of current exploitation or PoC.



