CVE-2017-16840

critical
Published 2017-11-21 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related to libavcodec/vc2enc.c and libavcodec/vc2enc_dwt.c.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2017-16840

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.debian.org/security/2017/dsa-4049

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/FFmpeg/FFmpeg/commit/94e538aebbc9f9c529e8b1f2eda860cfb8c473b1

OS impact

OSVersionStatusFixed in
arch archfixed1:3.4.1-1
debian debianbookwormfixed7:3.4.1-1
debian debianbullseyefixed7:3.4.1-1
debian debianforkyfixed7:3.4.1-1
debian debiansidfixed7:3.4.1-1
debian debiantrixiefixed7:3.4.1-1
debian debian9.0affected

Application impact

VendorProductVersionsFixed
ffmpegffmpeg3.0
ffmpegffmpeg3.4

References

CWEs

CWE-125

Verify integrity in audit chain (admin only). AS-IS.