PT-2026-68784 · FFmpeg+2 · Ffmpeg+2

·

CVE-2026-70628

·

Published

2026-08-06

·

Updated

2026-09-08

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FFmpeg versions 0.5 through 8.x
Description A signed integer overflow exists in the DVB subtitle parser within libavcodec/dvbsub parser.c. An attacker can trigger a heap buffer overflow by providing a specially crafted WTV file. This occurs when a bounds-check guard expression wraps to INT MIN, bypassing the PARSE BUF SIZE comparison. Consequently, the memcpy() function is called with attacker-controlled data, leading to an out-of-bounds heap write, which may result in memory corruption or arbitrary code execution.
Recommendations Update FFmpeg to version 9.0 or later.

Exploit

Fix

Memory Corruption

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70628
ECHO-6324-D2F6-0441
JLSEC-2026-1188
OPENSUSE-SU-2026:11659-1
OPENSUSE-SU-2026:11665-1
OPENSUSE-SU-2026:11682-1
OPENSUSE-SU-2026:11716-1
USN-8680-1
USN-8738-1

Affected Products

Ffmpeg
Linuxmint
Ubuntu