PT-2026-68788 · FFmpeg+2 · Ffmpeg+2

·

CVE-2026-70632

·

Published

2026-08-06

·

Updated

2026-09-08

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FFmpeg versions 4.4 through 8.x
Description An out-of-bounds heap write exists in the native GoPro CineForm HD (CFHD) decoder. A remote attacker can corrupt heap memory by providing a specially crafted AVI file during stream probing. The issue occurs because the cfhd decode() function does not enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path. This leads the horiz filter clip() function to write oversized 16-bit sample rows beyond the allocated output frame buffer, which may allow arbitrary code execution by overwriting a live cleanup callback pointer.
Recommendations Update FFmpeg to version 9.0 or later.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-70632
ECHO-D1BB-4D4F-3EA6
JLSEC-2026-1192
OPENSUSE-SU-2026:11659-1
OPENSUSE-SU-2026:11665-1
OPENSUSE-SU-2026:11682-1
OPENSUSE-SU-2026:11716-1
USN-8680-1
USN-8738-1

Affected Products

Ffmpeg
Linuxmint
Ubuntu