FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8 h_subpel_filters_outer
The vulnerability is located in the file libavcodec/ppc/vp8dsp_altivec.c, specifically in the static array h_subpel_filters_outer containing subpixel filters for VP8 codecs. When processing an appropriately crafted video stream, data is read beyond the boundaries of the allocated buffer. The error results from improper array indexing handling in code optimized for the AltiVec SIMD unit.
An attacker can cause disclosure of process memory contents (confidentiality breach) or unstable operation and crashes (denial of service — DoS). The attack vector is network-based and does not require authentication or user interaction.
Apply the patch available in the FFmpeg repository (commit 09e6840cf7a3ee07a73c3ae88a020bf27ca1a667) or update the package according to the distributor's recommendations (including Debian LTS — communication from February 2025). Update to a version containing the indicated fix according to the manufacturer's references.
FFmpeg version n6.1.1 running on PowerPC architecture with AltiVec support when processing VP8 video streams.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HFfmpeg
APPFfmpeg6.1.1
Related vulnerabilities
Double Free w FFmpeg — podatność w dekoderze RKMPP (libavcodec)
FFmpeg: Integer Overflow w parse_options (sbgdec.c) — moduł libavformat
FFmpeg: nieprawidłowa walidacja indeksu tablicy w dekodowaniu H.266
Integer overflow w FFmpeg — RCE przez parser JPEG XL
Integer overflow w FFmpeg — RCE przez dekoder animacji JPEG XL