CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-70629

mediumCVSS 5.5covered by 1 sourcefirst seen 2026-08-06
FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec/rscc.c) that allows attackers to disclose heap memory contents by supplying a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. When rscc_decode_frame() calls av_image_copy_plane() without validating the decompressed byte count against the tile dimensions, the unwritten suffix of the persistent intermediate buffer ctx->inflated_buf is copied into the decoded frame, potentially exposing data from prior heap allocations or previous decoded frames in persistent decoding services.

⚡ Watch CVE-2026-70629

Get an email if CVE-2026-70629 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (1)

External references

NVD record for CVE-2026-70629

CVE.org record

Embed the live status

CVE-2026-70629 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-70629 status](https://www.csirts.com/badge/CVE-2026-70629)](https://www.csirts.com/cve/CVE-2026-70629)