PT-2026-64155 · FFmpeg+3 · Ffmpeg+3

·

CVE-2026-65704

·

Published

2026-07-23

·

Updated

2026-09-09

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to 8.1.3
Description An out-of-bounds write issue exists when processing a crafted ffconcat file using the -safe 0 flag. The demux audio() function within the TY demuxer decrements the packet size without performing bounds checking. This results in a negative size value being passed to the memcpy() function inside shorten decode frame(). The subsequent conversion to size t causes the value to wrap to near SIZE MAX, leading to reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer, which causes heap corruption.
Recommendations Update to a version newer than 8.1.2. Avoid using the -safe 0 flag when processing ffconcat files.

Exploit

Fix

DoS

Memory Corruption

Integer Underflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65704
ECHO-7D2E-9FAD-304D
JLSEC-2026-1179
OESA-2026-3541
OESA-2026-3542
OESA-2026-3543
OESA-2026-3544
OESA-2026-3545
OPENSUSE-SU-2026:11545-1
OPENSUSE-SU-2026:11563-1
OPENSUSE-SU-2026:11665-1
OPENSUSE-SU-2026:11682-1
USN-8716-1
USN-8716-2

Affected Products

Ffmpeg
Linuxmint
Red Os
Ubuntu