FFmpeg n6.1.1 has a vulnerability in the WAVARC decoder of the libavcodec library which allows for an integer overflow when handling certain block types, leading to a denial-of-service (DoS) condition.
{
"cna_assigner": "mitre",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/36xxx/CVE-2024-36619.json"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-36619.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "324941801385009115336637907873512382711",
"length": 6012
},
"id": "CVE-2024-36619-830d574e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/ffmpeg/ffmpeg/commit/28c7094b25b689185155a6833caf2747b94774a4",
"target": {
"file": "libavcodec/wavarc.c",
"function": "decode_5elp"
}
}
]
"2026-08-18T17:27:00Z"