PT-2026-64415 · FFmpeg+3 · Ffmpeg+3

·

CVE-2026-66039

·

Published

2026-07-24

·

Updated

2026-09-08

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to 8.1.2
Description The MACE6 audio decoder contains a signed integer overflow that allows heap memory corruption via a crafted CAF file. By providing oversized bytes per packet and frames per packet values in the desc chunk, an attacker can trigger an integer overflow in the mace decode frame() function during the computation of the output sample count. This leads to an undersized buffer allocation and a heap out-of-bounds write, which could potentially enable arbitrary code execution.
Recommendations Update to the version containing commit aafb5c6. As a temporary mitigation, avoid processing CAF files using the MACE6 audio decoder.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66039
ECHO-96CC-EA04-811E
JLSEC-2026-1185
OESA-2026-3541
OESA-2026-3542
OESA-2026-3543
OESA-2026-3544
OESA-2026-3545
OPENSUSE-SU-2026:11448-1
OPENSUSE-SU-2026:11665-1
OPENSUSE-SU-2026:21522-1
OPENSUSE-SU-2026:21572-1
SUSE-SU-2026:23222-1
SUSE-SU-2026:23232-1
SUSE-SU-2026:3529-1
SUSE-SU-2026:3542-1
SUSE-SU-2026:3552-1
USN-8671-1
USN-8738-1

Affected Products

Ffmpeg
Linuxmint
Red Os
Ubuntu