A vulnerability, which was classified as problematic, was found in FFmpeg 8.0.1. Affected by this vulnerability is the function read_global_param of the file libavcodec/av1dec.c. Such manipulation leads to out-of-bounds read.

This vulnerability is referenced as CVE-2026-30997. It is possible to launch the attack remotely. No exploit is available.