- Sources: primary, discussion
- Summary: A fuzzer-found divide by zero in FFmpeg's VPK demuxer crashes on a 21-byte input that the demuxer probe self-identifies as VPK. Any application calling avformat_open_input and av_read_frame on untrusted data is reachable. The issue locates the defect at
libavformat/vpk.c line 89 and gives no affected-version scope, so which releases carry it is not yet known. A pull request to close the issue was opened on 2026-08-28. - Comments: An FFmpeg member replied on the issue that it appears to be the same defect as a November 2024 ffmpeg-devel thread.
- Why it matters: Media parsing runs on untrusted input in most upload pipelines, and a 21-byte crash input needs no valid container to reach the demuxer.
- Follow-up: Track whether the pull request lands and whether the November 2024 report covers the same code path.
send feedback on this story