To reproduce, host the attached files appropriately, and:
http://localhost/LoadMP4.swf?file=crash11077077.flv
If there is no crash at first, refresh the page a few times.
With a debugger attached to 64-bit Flash in Chrome Linux, the crash manifests like this:
=> 0x00007f48556b6050 <__memmove_ssse3_back+80>: movdqu (%rsi),%xmm0
rsi 0x7f4843b9f000
rdi 0x7f4843b8d000
rdx 0xc18 3096
7f4843144000-7f4843b9f000 rw-p 00000000 00:00 0
7f4843b9f000-7f4843bcd000 ---p 00000000 00:00 0
This bug is subject to a 90 day disclosure deadline. If 90 days elapse
without a broadly available patch, then the bug report will automatically
become visible to the public.