{"id":"CVE-2021-38092","details":"Integer Overflow vulnerability in function filter_prewitt in libavfilter/vf_convolution.c in Ffmpeg 4.2.1, allows attackers to cause a Denial of Service or other unspecified impacts.","modified":"2026-08-16T08:40:25.166664Z","published":"2021-09-20T16:15:11.363Z","related":["SUSE-SU-2021:3521-1","SUSE-SU-2023:0005-1","openSUSE-SU-2021:3521-1"],"references":[{"type":"REPORT","url":"https://trac.ffmpeg.org/ticket/8263"},{"type":"FIX","url":"https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/99f8d32129dd233d4eb2efa44678a0bc44869f23"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.ffmpeg.org/ffmpeg.git","events":[{"introduced":"0"},{"fixed":"99f8d32129dd233d4eb2efa44678a0bc44869f23"}],"database_specific":{"source":"REFERENCES"}}],"versions":["n4.3-dev","n4.2-dev","n4.1-dev","n3.5-dev","n3.4-dev","n3.3-dev","n3.2-dev","n3.1-dev","n2.9-dev","n2.8-dev","n2.7-dev","n2.6-dev","n2.5-dev","n2.4-dev","n2.3-dev","n2.2-dev","n2.0","n2.1-dev","n1.3-dev","n1.2-dev","n1.1-dev","n0.12-dev","n0.11-dev","n0.8","N"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-38092.json","vanir_signatures_modified":"2026-08-16T08:40:25Z","vanir_signatures":[{"signature_version":"v1","source":"https://git.ffmpeg.org/ffmpeg.git@99f8d32129dd233d4eb2efa44678a0bc44869f23","target":{"file":"libavfilter/vf_convolution.c"},"deprecated":false,"digest":{"line_hashes":["312273638365972571766734284783019729603","285567748274445502065394555650402803121","327398328860241102843078614973482077537","117681638743582263217945923413007996537","222534626823148156791322086811346367960","149602235256029141960719439084693980688","103808034539985284971036791061038568826","101039381615351325400305736652849788366","119693142047805769029490076729578745116","139452788001286772171967991528251165274","177940589039421921850201029768046208390","244997580765275798099686519915370111041","3914800900619165334279620183313968222","44518601934018282101502064419566480060","62518029836362370285263512850360305238","189470130817758884447871425458746443450","78653062183009480022319953671287788912","114444927211754860249863075764691162908","66285443371216913387989060555134956562","309978362299586124551737786328047743407","259298084354075942386572987322614529070","186831038704776475693405517368196539400","289143565420298446379454232965136318157","336354824418643347393096241341468903757","99509090908342416414817712154805222512","289649847330572877479786622807536475459","68625682147658959016558056212637336871","261652877277890744184300833283052407301","122681924982441369086370075581982510861","294876380691225843837702040655334511178","292745019692913569079526383476247624480","313485597580227832005924366183174226831","24821684458328961796810943869477170565","226862523343509285969745652283740131482","116395643705848526885047825812765649904","50546107077065024187201985613306465974","164292349910039431187897681673784197165","33663597916244604844398142176930137897"],"threshold":0.9},"id":"CVE-2021-38092-47770ae8","signature_type":"Line"}]}},{"ranges":[{"type":"GIT","repo":"https://github.com/ffmpeg/ffmpeg","events":[{"introduced":"1529dfb73a5157dcb8762051ec4c8d8341762478"},{"last_affected":"1529dfb73a5157dcb8762051ec4c8d8341762478"}],"database_specific":{"cpe":"cpe:2.3:a:ffmpeg:ffmpeg:4.2.1:*:*:*:*:*:*:*","extracted_events":[{"introduced":"4.2.1"},{"last_affected":"4.2.1"}],"source":"CPE_STRING"}}],"versions":["4.2.1","n4.2.1"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-38092.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}