PatchSiren

FFmpeg CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM FFmpeg CVE published 2026-09-23

CVE-2026-96611

A vulnerability in FFmpeg before version 9.0 can cause a signed integer overflow when processing crafted HEIF files. This occurs because the mov_read_ispe() function stores uint32_t width and height values from the HEIF ispe box into signed int fields without bounds checking. As a result, large values can become negative, leading to undefined behavior when these values are accumulated in the read_image_gr [truncated]

LOW FFmpeg CVE published 2026-09-13

CVE-2026-52297

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-13T22:17:00.433Z and has not been modified since then. The vulnerability is an out-of-bounds read issue in FFmpeg before version 9.0, caused by insufficiently padded extradata in the MOV parsing path. Defenders should prioritize verifying FFmpeg versions and updating to 9.0 or later if necessary. Th [truncated]

LOW FFmpeg CVE published 2026-09-13

CVE-2026-52296

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-13T22:17:00.297Z and has not been modified since then. This low-severity vulnerability in FFmpeg, caused by missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c., could lead to information disclosure. Defenders responsible for media processing systems, FFmpeg deployments [truncated]

LOW FFmpeg CVE published 2026-09-01

CVE-2026-52295

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-09-01T18:17:43.940Z and has not been modified since then. This low-severity vulnerability affects FFmpeg versions 7.0 and later, specifically in libavformat/iamf_writer.c, due to insufficient padding in extradata before GetBitContext-based access. Defenders responsible for FFmpeg deployments, media fil [truncated]

HIGH FFmpeg CVE published 2026-08-28

CVE-2026-38347

A heap overflow in the ff_sws_alphablendaway function of FFmpeg allows attackers to cause a Denial of Service (DoS) via a crafted input. The CVE record was published on 2026-08-28T00:17:27.420Z and has not been modified since then. This vulnerability affects users of FFmpeg, particularly those processing untrusted input. Affected systems should be reviewed for compensating controls and monitoring while re [truncated]

MEDIUM FFmpeg CVE published 2026-08-28

CVE-2026-38345

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-28T00:17:27.197Z and has not been modified since then. A Division-by-Zero vulnerability exists in the ff_sws_init_single_context function of FFmpeg, which allows attackers to cause a Denial of Service (DoS) via a crafted input. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. This [truncated]

HIGH FFmpeg CVE published 2026-08-28

CVE-2026-38344

A NULL pointer dereference vulnerability was found in the get_min_buffer_size function of FFmpeg. This issue allows attackers to cause a Denial of Service (DoS) via a crafted video file. The vulnerability affects FFmpeg version N-122528-gdd2976b9e1, located in /libswscale/slice.c. Organizations should assess potential exposure and implement compensating controls if necessary. Further analysis is needed to [truncated]

MEDIUM FFmpeg CVE published 2026-08-28

CVE-2026-38343

An integer overflow vulnerability was reported in the libavfilter/vf_scale.c component of FFmpeg. This issue allows attackers to cause a Denial of Service (DoS) via a crafted video file. The vulnerability has a CVSS score of 6.5 and a severity of MEDIUM. Developers and administrators should verify their FFmpeg installations for the vulnerable component and restrict input to trusted sources.

MEDIUM FFmpeg CVE published 2026-08-19

CVE-2026-75147

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T17:21:13.290Z and has not been modified since then. The NVD entry is currently 6.9 MEDIUM. FFmpeg's AV1 RTP packetizer has an out-of-bounds read vulnerability due to improper validation of OBU sizes in the RTPenc_av1.c file. A crafted AV1 input packet can cause the packetizer to dereference a poi [truncated]

HIGH FFmpeg CVE published 2026-08-19

CVE-2026-75146

The DASH demuxer (libavformat/dashdec.c) in FFmpeg before commit 65b0dab contains an out-of-bounds read vulnerability. This issue arises when a live DASH manifest is refreshed with a startNumber that is lower than the previous value, causing the current sequence number to be driven negative. The fragment retrieval function checked only the upper bound before indexing the fragments array, allowing a negati [truncated]

HIGH FFmpeg CVE published 2026-08-19

CVE-2026-75144

The CVE-2026-75144 vulnerability is a heap buffer overflow in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) in FFmpeg before commit 1cdeb3c. This vulnerability allows attackers to trigger memory corruption by supplying a crafted Dirac data unit. The packetizer copies an input-derived data unit or fragment size into a fixed-size buffer without an upper bound check, causing a heap buffer overfl [truncated]

CRITICAL FFmpeg CVE published 2026-08-19

CVE-2026-75143

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-19T17:21:12.577Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. The FFmpeg library before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader. The issue arises from the librist_read() function ignoring its size argument and copying the full [truncated]

HIGH FFmpeg CVE published 2026-08-19

CVE-2026-75142

A stack buffer overflow vulnerability exists in FFmpeg before commit 9d786e4 in the MPEG-PS muxer (libavformat/mpegenc.c). The vulnerability is triggered when muxing input with more streams than the muxer's fixed-size stack buffer accommodates, causing a buffer overflow. A crafted input with an excessive number of streams can trigger the overflow during MPEG-PS muxing.

HIGH FFmpeg CVE published 2026-08-06

CVE-2026-70632

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:18:27.567Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. This out-of-bounds heap write vulnerability in FFmpeg versions from 4.4 up to, but not including, 9.0 allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream prob [truncated]

MEDIUM FFmpeg CVE published 2026-08-06

CVE-2026-70631

The CVE-2026-70631 vulnerability is an uninitialized heap memory disclosure issue in FFmpeg's native TIFF decoder. This vulnerability can cause FFmpeg to decode a crafted TIFF file, potentially exposing sensitive data in persistent services. Organizations using FFmpeg for TIFF file processing should prioritize patching to prevent potential sensitive data exposure. The CVE record was published on 2026-08-0 [truncated]

MEDIUM FFmpeg CVE published 2026-08-06

CVE-2026-70630

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:18:27.273Z and has not been modified since then. The NVD entry is currently Awaiting Analysis. The vulnerability affects FFmpeg versions from 3.0 up to, but not including, 9.0. The screenpresso_decode_frame() function in FFmpeg's native Screenpresso decoder fails to validate the produced byte [truncated]

MEDIUM FFmpeg CVE published 2026-08-06

CVE-2026-70629

The CVE-2026-70629 vulnerability is an uninitialized heap memory read issue in the native RSCC decoder of FFmpeg versions from 3.0 up to, but not including, 9.0. This vulnerability allows attackers to disclose heap memory contents by providing a crafted video file with a compressed tile that decompresses fewer bytes than the declared tile geometry requires. The issue arises from the rscc_decode_frame() fu [truncated]

HIGH FFmpeg CVE published 2026-08-06

CVE-2026-70628

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:18:26.957Z and has not been modified since then. The CVE-2026-70628 vulnerability is caused by a signed integer overflow in the DVB subtitle parser of FFmpeg, which can lead to a heap buffer overflow when processing a crafted WTV file. The issue affects FFmpeg versions from 0.5 up to, but not [truncated]

HIGH FFmpeg CVE published 2026-07-24

CVE-2026-66040

CVE-2026-66040 is a high-severity vulnerability in FFmpeg's native PNG and APNG encoders. It allows remote attackers to corrupt heap memory via a crafted PNG eXIf chunk, potentially leading to process crashes and arbitrary code execution. This vulnerability is particularly concerning due to its potential for heap corruption and code execution, emphasizing the need for immediate patching. Users and organiz [truncated]

HIGH FFmpeg CVE published 2026-07-24

CVE-2026-66039

CVE-2026-66039 is a high-severity vulnerability in FFmpeg's MACE6 audio decoder. It allows attackers to corrupt heap memory by supplying a crafted CAF file, potentially enabling code execution. The vulnerability exists due to a signed integer overflow in the mace_decode_frame() function during output sample count computation. This results in an undersized buffer allocation and a subsequent heap out-of-bou [truncated]

HIGH FFmpeg CVE published 2026-07-24

CVE-2026-66038

CVE-2026-66038 is an information disclosure vulnerability in the LCL/ZLIB video decoder of FFmpeg, a popular open-source multimedia processing tool. The vulnerability allows attackers to expose uninitialized heap memory by providing a specially crafted zlib stream that decompresses to fewer bytes than expected. This can lead to the exposure of sensitive information, including uninitialized heap contents a [truncated]

HIGH FFmpeg CVE published 2026-07-24

CVE-2026-66037

CVE-2026-66037 is an uncontrolled resource consumption vulnerability in the IAMF demuxer of FFmpeg. The vulnerability allows an unauthenticated attacker to cause multi-gigabyte memory allocation from a 17-byte input file by supplying a crafted count_label field. The mix_presentation_obu() function in libavformat/iamf_parse.c calls av_calloc(count_label, sizeof(*language_label)) with an attacker-controlled [truncated]

HIGH FFmpeg CVE published 2026-07-24

CVE-2026-66036

A heap out-of-bounds write vulnerability exists in FFmpeg's vf_hqdn3d filter. This vulnerability allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. The vulnerability was fixed in commit 5d7112c. The affected product is FFmpeg, and the vulnerability class is a hea [truncated]

HIGH FFmpeg CVE published 2026-07-23

CVE-2026-65706

CVE-2026-65706 is an out-of-bounds write vulnerability in the vf_swaprect video filter of FFmpeg versions 3.0 through 8.1.2. The vulnerability allows attackers to corrupt heap memory by supplying a crafted NV12 video frame with odd width dimensions. This occurs because the filter_frame() function reuses a temporary row buffer sized for plane 0's single-byte pixel step across all planes, causing an 18-byte [truncated]

HIGH FFmpeg CVE published 2026-07-23

CVE-2026-65705

CVE-2026-65705 is an out-of-bounds write vulnerability in the vf_floodfill video filter of FFmpeg versions 3.4 through 8.1.2. The vulnerability allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent large [truncated]

HIGH FFmpeg CVE published 2026-07-23

CVE-2026-65704

CVE-2026-65704 is an out-of-bounds write vulnerability in FFmpeg through 8.1.2. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(). This triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer. The vulnerability can be exploited by suppl [truncated]

HIGH FFmpeg CVE published 2026-07-23

CVE-2026-65703

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T20:17:21.803Z and has not been modified since then. This out-of-bounds write vulnerability in the TDSC video decoder of FFmpeg versions 2.7 through 8.1.2 allows remote attackers to cause heap corruption by supplying a crafted AVI file. The vulnerability has a high impact due to its potential for [truncated]

HIGH FFmpeg CVE published 2026-07-22

CVE-2026-64834

CVE-2026-64834 is an infinite loop vulnerability in the RTP/ASF demuxer within libavformat/rtpdec_asf.c in FFmpeg versions 0.6.3 through 8.1.2. The vulnerability allows remote attackers to cause denial of service by sending a crafted RTP/ASF stream. The rtp_asf_fix_header function fails to validate a minimum chunksize when iterating over ASF objects, causing the loop pointer to never advance when a chunks [truncated]

HIGH FFmpeg CVE published 2026-07-22

CVE-2026-64833

CVE-2026-64833 is an out-of-bounds read vulnerability in the S/PDIF muxer of FFmpeg versions 0.7.1 through 8.1.2. The vulnerability allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. This can be exploited during S/PDIF re-muxing to trigger unauthorized memory reads. The vulnerability has a high severity [truncated]

HIGH FFmpeg CVE published 2026-07-22

CVE-2026-64832

A high-severity double-free vulnerability was discovered in FFmpeg versions 4.4 through 8.1.2, affecting the NVIDIA NVDEC hardware decoder. This vulnerability, tracked as CVE-2026-64832, allows attackers to trigger memory corruption by supplying a crafted video file. The vulnerability is caused by the ff_nvdec_start_frame_sep_ref error path freeing memory via nvdec_fdd_priv_free, while the calling layer s [truncated]