Just in:
Haldwani purification row: Caste back on political centre-stage // Jungheinrich Marks 25 Years In Singapore, Leading APAC Strategic Hub And Electrification In The Market // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Qatar economy contracts 7% as energy output slumps // Adobe widens Saudi AI access with $4 billion programme // SCX Corporation Accelerates SC Group’s Recurring-Income Businesses // Putin holds talks with Pezeshkian in Bishkek // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // What Shein’s $27bn IPO means for Mubadala // India plans own orbital space outpost, second after China // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents // Russia brings cryptocurrency market law into force // Alpha Dhabi lifts MICAD commitment to $1 billion // US-Iran strikes revive confrontation across Hormuz and Jordan // Apple raises evidence-destruction claims against OpenAI // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // Best Mart 360 Reports Interim Revenue Growth to HK$1.45 billion // XcanMow Mix 2000 Robot Mower Makes Its European Debut at IFA Berlin 2026 // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click //

FFmpeg flaws expose media pipelines to memory attacks

Multiple high-severity vulnerabilities in FFmpeg have exposed media-processing systems to memory corruption, information leakage and service disruption when they handle malicious video, audio, image or subtitle files.

The newly catalogued flaws affect FFmpeg 8.1.2 and, depending on the vulnerability, several older branches. They are especially significant for cloud transcoding services, streaming platforms, social networks, content-management systems and artificial intelligence applications that automatically process files supplied by users.

Security records identify weaknesses across FFmpeg’s decoders, encoders, filters, demuxers and hardware-acceleration components. Several could permit writes outside allocated memory, creating conditions that may crash an application or potentially allow an attacker to execute code within the affected process.

One of the most serious issues, tracked as CVE-2026-64830, is a heap-buffer overflow in the VobSub subtitle demuxer. A specially prepared pair of. sub and. idx files can declare more subtitle stream identifiers than an internal fixed-size array can accommodate. Processing the files may cause data to be written into adjacent heap memory.

The flaw affects FFmpeg versions from 2.1 through 8.1.2 and carries a high severity rating. Successful exploitation requires a targeted file to be processed, but this interaction may occur automatically when an upload service extracts subtitles, metadata or preview images.

A separate vulnerability, CVE-2026-64832, affects the NVIDIA NVDEC hardware decoder used to accelerate video decoding on supported graphics processors. Crafted video content can trigger a double-free condition, in which the software attempts to release the same memory location twice. Such errors can corrupt memory and may become exploitable under favourable conditions.

The NVDEC weakness affects FFmpeg versions 4.4 through 8.1.2. Systems without the relevant NVIDIA decoding path may not be directly exposed to that particular flaw, although installations often contain multiple vulnerable components.

Other defects broaden the potential attack surface beyond conventional video playback. CVE-2026-64833 involves an out-of-bounds read in the S/PDIF muxer. A malicious DTS-HD audio stream can supply a false size value, prompting FFmpeg to read beyond the packet buffer. The result could be a crash or disclosure of data held near the affected memory region.

Information exposure is also possible through CVE-2026-66038 in the LCL/ZLIB video decoder. The decoder can accept a compressed stream that produces less data than expected, then continue copying a complete frame from a partly uninitialised allocation. Output generated during processing could therefore contain fragments of heap memory belonging to the FFmpeg process.

Such leakage may reveal pointer values or other process data that could help an attacker bypass protections including address space layout randomisation. It may also become part of a multi-stage exploit when combined with a separate memory-writing vulnerability.

Additional out-of-bounds write flaws have been identified in FFmpeg video filters. CVE-2026-65705 affects the flood-fill filter when frame dimensions change while automatic filtergraph reinitialisation is disabled. CVE-2026-65706 affects the rectangle-swapping filter when it processes specially formed NV12 frames with odd widths.

CVE-2026-66036 similarly targets the hqdn3d denoising filter through video streams whose resolution changes between frames under particular filter settings. Another weakness affects the native PNG and animated PNG encoders, where malicious metadata can cause heap memory corruption while images are processed.

Not every vulnerable function is enabled or reached in a standard installation. Exploitability depends on build options, command-line parameters, hardware support and the way a downstream application invokes FFmpeg. Public upload portals and unattended conversion systems face greater exposure because attackers can repeatedly submit files without directly operating the affected server.

The risk extends beyond machines where administrators knowingly installed the FFmpeg command-line utility. Its libraries are embedded or bundled in desktop programs, mobile applications, browser components, surveillance platforms, messaging systems and machine-learning services. Statically linked copies may remain hidden from conventional package inventories and may not receive operating-system updates.

Organisations are being advised to identify every deployed FFmpeg instance, including copies packaged inside containers, appliances and third-party applications. Upgrading only the system package may leave bundled binaries unchanged.

The official stable 8.1 branch release listed before these latest disclosures is FFmpeg 8.1.2, released on 17 June. Contrary to claims circulating in some reports, there is no official FFmpeg version 8.1.28. Several July vulnerability notices state that versions through 8.1.2 are affected and point to individual source-code commits as fixes, meaning users may need vendor patches or development builds containing the relevant changes.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in:
Best Mart 360 Reports Interim Revenue Growth to HK$1.45 billion // Adobe widens Saudi AI access with $4 billion programme // XcanMow Mix 2000 Robot Mower Makes Its European Debut at IFA Berlin 2026 // Alpha Dhabi lifts MICAD commitment to $1 billion // InnoHK R&D Centres Establish Base at Science Park to Drive Emerging Industries and Pioneer Future Innovation // Haldwani purification row: Caste back on political centre-stage // What Shein’s $27bn IPO means for Mubadala // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Venezuela defends sovereignty after Trump oil control claim // Qatar economy contracts 7% as energy output slumps // Amicura X1 Max Smart Cat Litter Box:AliExpress France Official Warehouse, Litter Box at One Click // US-Iran strikes revive confrontation across Hormuz and Jordan // Jordan downs eight missiles as Iran targets US bases // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // Trump rejects munitions fears as Iran clashes resume // Chinese researchers engineer self-contracting muscle grafts // Jungheinrich Marks 25 Years In Singapore, Leading APAC Strategic Hub And Electrification In The Market // WisPaper Introduces TrueCite to Help Researchers Verify AI-Generated Academic References // Apple raises evidence-destruction claims against OpenAI // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” //