PT-2026-63434 · FFmpeg+3 · Ffmpeg+3

CVE-2026-64830

·

Published

2026-07-22

·

Updated

2026-09-09

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg versions 2.1 through 8.1.2
Description A heap buffer overflow exists in the VobSub subtitle demuxer. An attacker can corrupt adjacent heap memory by providing a malicious .sub/.idx subtitle file that declares more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. This allows unbounded writes beyond the vobsub->q[] array boundary through the ff subtitles queue insert() function, which could lead to arbitrary code execution in applications utilizing the VobSub demuxer.
Recommendations Update FFmpeg to a version later than 8.1.2. As a temporary workaround, avoid processing untrusted .sub/.idx subtitle files using the VobSub demuxer.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64830
ECHO-F134-A339-73A5
JLSEC-2026-1172
OESA-2026-3541
OESA-2026-3542
OESA-2026-3543
OESA-2026-3544
OESA-2026-3545
OPENSUSE-SU-2026:11448-1
OPENSUSE-SU-2026:11665-1
OPENSUSE-SU-2026:21522-1
OPENSUSE-SU-2026:21572-1
SUSE-SU-2026:23222-1
SUSE-SU-2026:23232-1
SUSE-SU-2026:3529-1
SUSE-SU-2026:3542-1
SUSE-SU-2026:3552-1
USN-8716-1
USN-8716-2

Affected Products

Ffmpeg
Linuxmint
Red Os
Ubuntu