A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be carried out remotely. Upgrading to version 8.1 and 9.0 is able to mitigate this issue. The patch is named 64fafd63f0b4. Upgrading the affected component is recommended.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 20:17
Updated : 2026-09-15 20:19
NVD link : CVE-2026-90816
Mitre link : CVE-2026-90816
CVE.ORG link : CVE-2026-90816
JSON object : View
Products Affected
No product.
CWE
CWE-404
Improper Resource Shutdown or Release
