CVE-2026-107678: FFmpeg through 9.0.2 Stack Exhaustion via Recursive Free of pssh Boxes
FFmpeg through 9.0.2 contains a stack exhaustion vulnerability in avencryptioninitinfofree() in libavutil/encryptioninfo.c, which recursively frees AVEncryptionInitInfo linked lists built by the MOV demuxer's movreadpssh(). Attackers can supply a crafted MP4 file with tens of thousands of small pssh boxes to exhaust the stack and crash the process, while also causing quadratic CPU consumption.
Affected Software
Event History
Frequently Asked Questions
Which deployments are realistically exposed?
Applications that use affected FFmpeg versions to process attacker-supplied MP4 files are exposed. The vulnerable path is the MOV demuxer's handling of pssh boxes.
What does an attacker need to trigger the issue?
An attacker needs to supply a crafted MP4 containing tens of thousands of small pssh boxes. Processing that file can exhaust the stack during recursive cleanup and crash the process.
Is the impact limited to a crash?
No. The crafted pssh-box structure can also cause quadratic CPU consumption while the file is processed.