{"schema_version":"1.7.2","id":"OESA-2026-3877","modified":"2026-09-20T13:22:49Z","published":"2026-09-20T13:22:49Z","upstream":["CVE-2023-6604"],"summary":"ffmpeg security update","details":"FFmpeg is a complete and free Internet live audio and video broadcasting solution for Linux/Unix. It also includes a digital VCR. It can encode in real time in many formats including MPEG1 audio and video, MPEG4, h263, ac3, asf, avi, real, mjpeg, and flash.\r\n\r\nSecurity Fix(es):\n\nA flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.(CVE-2023-6604)","affected":[{"package":{"ecosystem":"openEuler:20.03-LTS-SP4","name":"ffmpeg","purl":"pkg:rpm/openEuler/ffmpeg&distro=openEuler-20.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.4-56.oe2003sp4"}]}],"ecosystem_specific":{"aarch64":["ffmpeg-4.2.4-56.oe2003sp4.aarch64.rpm","ffmpeg-debuginfo-4.2.4-56.oe2003sp4.aarch64.rpm","ffmpeg-debugsource-4.2.4-56.oe2003sp4.aarch64.rpm","ffmpeg-devel-4.2.4-56.oe2003sp4.aarch64.rpm","ffmpeg-libs-4.2.4-56.oe2003sp4.aarch64.rpm","libavdevice-4.2.4-56.oe2003sp4.aarch64.rpm"],"src":["ffmpeg-4.2.4-56.oe2003sp4.src.rpm"],"x86_64":["ffmpeg-4.2.4-56.oe2003sp4.x86_64.rpm","ffmpeg-debuginfo-4.2.4-56.oe2003sp4.x86_64.rpm","ffmpeg-debugsource-4.2.4-56.oe2003sp4.x86_64.rpm","ffmpeg-devel-4.2.4-56.oe2003sp4.x86_64.rpm","ffmpeg-libs-4.2.4-56.oe2003sp4.x86_64.rpm","libavdevice-4.2.4-56.oe2003sp4.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3877"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6604"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}],"database_specific":{"severity":"Medium"}}
