CVE-2020-12284: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.
cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check.
Affected products
- Canonical Ubuntu Linux: version 16.04 only; version 18.04 only; version 20.04 only
- Debian Debian Linux: version 10.0 only
- Ffmpeg Ffmpeg: version 4.1 only; version 4.2.2 only
Published 2020-04-28. Last modified 2026-06-17.