Hello.
This is a bug found with our fuzzer: https://github.com/daedalus/fuzzer/
**File**: `libavformat/vpk.c:89`
**Severity**: Medium — crafted 21-byte input crashes any FFmpeg-based application that opens a malicious `.vpk` file or stream
**Root cause**: `vpk_read_packet` divides `vpk->l...
With a history like ffmpegs, it’s just very likely that fuzzer findings have already been reported once. That the fuzzer is vibecoded is kinda irrelevant
With a history like ffmpegs, it’s just very likely that fuzzer findings have already been reported once. That the fuzzer is vibecoded is kinda irrelevant