PatchSiren cyber security CVE debrief
CVE-2026-70632 FFmpeg CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:18:27.567Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This out-of-bounds heap write vulnerability in FFmpeg versions from 4.4 up to, but not including, 9.0 allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing, potentially leading to arbitrary code execution. Users and administrators of FFmpeg installations, particularly those using versions from 4.4 up to, but not including, 9.0, should be aware of this vulnerability and take defensive actions to mitigate potential exploitation attempts. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer. Evidence is based on official CVE Program record and NVD vulnerability detail.
- Vendor
- FFmpeg
- Product
- Unknown
- CVSS
- HIGH 8.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-06
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-06
- Advisory updated
- 2026-08-31
Who should care
Users and administrators of FFmpeg installations, particularly those using versions from 4.4 up to, but not including, 9.0, should be aware of this vulnerability and take defensive actions to mitigate potential exploitation attempts.
Technical summary
The cfhd_decode() function in FFmpeg versions from 4.4 up to, but not including, 9.0 fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer.
Defensive priority
High-priority defensive actions are required to address the out-of-bounds heap write vulnerability in FFmpeg versions from 4.4 up to, but not including, 9.0.
Recommended defensive actions
- Inventory FFmpeg installations and verify versions are within the affected range.
- Apply patches or updates from the FFmpeg project to address the vulnerability.
- Implement compensating controls, such as monitoring and exception tracking, to detect potential exploitation attempts.
- Restrict access to AVI files and limit the use of the CFHD decoder.
- Consider using alternative decoders or media processing tools.
Evidence notes
The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer. Evidence is based on official CVE Program record and NVD vulnerability detail.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-70632 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-70632
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-70632 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-70632
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e
-
Source reference
Unverified legacy reference
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9
-
Source reference
Unverified legacy reference
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087
-
Source reference
Unverified legacy reference
URL: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxing
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.