FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than the muxer's fixed-size stack buffer accommodates, the buffer is overflowed. A crafted input with an excessive number of streams triggers the overflow during MPEG-PS muxing.
{
"cna_assigner": "VulnCheck",
"cwe_ids": [
"CWE-121"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75142.json"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-75142.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"114639654182095632047070235152466210081",
"249610853207856935291400141385738400980",
"33200706439079886469472669656279397739",
"39790311004898067853887037964310431355"
],
"threshold": 0.9
},
"id": "CVE-2026-75142-3eff7f84",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://code.ffmpeg.org/FFmpeg/FFmpeg@9d786e4b5e9b8482651928574de33772aeee7be1",
"target": {
"file": "libavformat/mpegenc.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "232601109389363913409863017295252059792",
"length": 7932
},
"id": "CVE-2026-75142-dde7156e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://code.ffmpeg.org/FFmpeg/FFmpeg@9d786e4b5e9b8482651928574de33772aeee7be1",
"target": {
"file": "libavformat/mpegenc.c",
"function": "mpeg_mux_init"
}
}
]
"2026-09-30T08:16:42Z"