Hello.
This is a bug found with our fuzzer: https://github.com/daedalus/fuzzer/
**File**: `libavformat/vpk.c:89`
**Severity**: Medium — crafted 21-byte input crashes any FFmpeg-based application that opens a malicious `.vpk` file or stream
**Root cause**: `vpk_read_packet` divides `vpk->l...
In theory they can “find” new things, but typically it’s based on other training data.
Do you mean LLMs can find new bug classes or new bugs?
New bugs, not bug classes.
They also seem to do well with chaining low severity vulnerabilities to result in an overall high severity exploit.