• Sources: primary, discussion
  • Summary: A fuzzer-found divide by zero in FFmpeg's VPK demuxer crashes on a 21-byte input that the demuxer probe self-identifies as VPK. Any application calling avformat_open_input and av_read_frame on untrusted data is reachable. The issue locates the defect at libavformat/vpk.c line 89 and gives no affected-version scope, so which releases carry it is not yet known. A pull request to close the issue was opened on 2026-08-28.
  • Comments: An FFmpeg member replied on the issue that it appears to be the same defect as a November 2024 ffmpeg-devel thread.
  • Why it matters: Media parsing runs on untrusted input in most upload pipelines, and a 21-byte crash input needs no valid container to reach the demuxer.
  • Follow-up: Track whether the pull request lands and whether the November 2024 report covers the same code path.

send feedback on this story