CVE-2026-30754

high

Description

A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size parameter (size=-3) is passed to memcpy when transmitting H.264/HEVC streams via RTP using a crafted input file. This was detected using AddressSanitizer.

References

https://github.com/momo-trip/poc_ffmpeg

https://gist.github.com/momo-trip/4cddf2c9e15600873de55259dac6b0e6

https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20746

Details

Source: Mitre, NVD

Published: 2026-09-08

Updated: 2026-09-09

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00166