• richmondez@lemdro.id
    link
    fedilink
    English
    arrow-up
    41
    arrow-down
    1
    ·
    5 小时前

    What these articles never say is how many hallucinated bugs the LLM found that either weren’t real or were actually exploitable. The LLM didn’t find these with any confidence it highlighted areas of interest that actual security researchers then needed to investigate and confirm or rule out.

  • greyscale@lemmy.grey.ooo
    link
    fedilink
    English
    arrow-up
    39
    arrow-down
    14
    ·
    7 小时前

    What the fuck is a zero day in the context of ffmpeg?

    Its not like its a system service that you can get ingress through…

    “AI found 21 bugs in massive video project” sounds like junior developer shit hungry to get some shit on their resume.

    Even if it wasn’t AI slop, this wouldn’t be impressive.

    • karlhungus@lemmy.ca
      link
      fedilink
      English
      arrow-up
      13
      ·
      4 小时前

      My understanding is that ffmpeg is the bedrock that all video streaming services use. I’m suspicious it’s a bigger deal than you think

    • VibeSurgeon@piefed.social
      link
      fedilink
      English
      arrow-up
      27
      ·
      6 小时前

      Its not like its a system service that you can get ingress through…

      With a competently crafted payload, you could perhaps get in via someone’s transcoding pipeline.

      • greyscale@lemmy.grey.ooo
        link
        fedilink
        English
        arrow-up
        6
        arrow-down
        3
        ·
        6 小时前

        Does nobody isolate ffmpeg and friends from their application?

        I can’t imagine you’d have much fun breaking into a container that terminates the moment the original ffmpeg stops, or over-runs its max execution time…

          • Passerby6497@lemmy.world
            link
            fedilink
            English
            arrow-up
            5
            ·
            5 小时前

            If you’re running rootless containers, it’s less of a concern. I’m trying to move all of my public containers to podman for this reason

    • Zarxrax@lemmy.world
      link
      fedilink
      English
      arrow-up
      18
      ·
      6 小时前

      From the article

      Most are heap or stack overflows in parsers and demuxers, spanning components from the TS demuxer to the VP9 decoder. depthfirst says some already carry CVE identifiers; its writeup lists nine, CVE-2026-39210 through CVE-2026-39218, and notes the rest are fixed but not yet numbered. It also published a PoC.

    • fonix232@fedia.io
      link
      fedilink
      arrow-up
      9
      arrow-down
      2
      ·
      5 小时前

      Tell me you know nothing about the intricacies of media playback (especially hardware accelerated), without telling me…

    • tomalley8342@lemmy.world
      link
      fedilink
      English
      arrow-up
      11
      ·
      6 小时前

      I imagine there are many web services around the world which use ffmpeg to handle user submitted content.

    • themurphy@lemmy.ml
      link
      fedilink
      English
      arrow-up
      7
      arrow-down
      15
      ·
      7 小时前

      Discovering bugs is not “AI slop”.

      That term refers to something the AI made. This is just product testing, where a real human then fixes it as intended.

      • finalarbiter@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        6
        ·
        2 小时前

        Manny moderate to large open source projects are effectively being ddosed by vibe coders submitting hallucinated and non-issue bug reports sometime because claude or copilot said so. Those reports are absolutely slop, no different from anything else generative ai platforms shit out.

        But sure, go off on how this particular kind of output from an LLM is somehow different from rest.