CVE-2024-31581: Fedoraproject Fedora

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c. This vulnerability allows attackers to cause undefined behavior within the application.

Affected products

  • Fedoraproject Fedora: version 38 only; version 39 only; version 40 only
  • Ffmpeg Ffmpeg: version 6.1 only

Published 2024-04-17. Last modified 2026-06-17.