A vulnerability classified as problematic has been found in FFmpeg up to 8.1.1. This affects the function mix_presentation_obu of the file libavformat/iamf_parse.c of the component IAMF demuxer. This manipulation of the argument count_label causes resource consumption.

This vulnerability is handled as CVE-2026-66037. The attack can be initiated remotely. There is not any exploit available.

To fix this issue, it is recommended to deploy a patch.