A vulnerability classified as problematic has been found in FFmpeg up to 8.1.1. This affects the function
mix_presentation_obu of the file libavformat/iamf_parse.c of the component IAMF demuxer. This manipulation of the argument count_label causes resource consumption.
This vulnerability is handled as CVE-2026-66037. The attack can be initiated remotely. There is not any exploit available.
To fix this issue, it is recommended to deploy a patch.