A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when processing crafted TDSC cursor data. A remote attacker could exploit this by supplying a specially crafted video file, potentially leading to a denial of service or arbitrary code execution.
{
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18393.json"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-18393.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"132926603633619437789564998802531084012",
"5115286422503886191163899541961563008",
"96726760300170213713591501441628314041",
"91104098611128400657983985119675472894",
"132926603633619437789564998802531084012",
"5115286422503886191163899541961563008",
"55813710358584922178425752992249684987",
"331985906405930370156508052252427014409"
],
"threshold": 0.9
},
"id": "CVE-2026-18393-e2aa7986",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/ffmpeg/ffmpeg/commit/242ff799c75f20bade946314c8d741d0887ee11c",
"target": {
"file": "libavcodec/tdsc.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "149856160101408485285483853934977017196",
"length": 3332
},
"id": "CVE-2026-18393-f96efe34",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/ffmpeg/ffmpeg/commit/242ff799c75f20bade946314c8d741d0887ee11c",
"target": {
"file": "libavcodec/tdsc.c",
"function": "tdsc_load_cursor"
}
}
]
"2026-08-30T08:06:12Z"