CVE-2026-66039
Security update for ffmpeg-4
Beschreibung
FFmpeg bis Version 8.1.2 enthält eine Schwachstelle durch einen Überlauf eines signierten Ganzzahls im MACE6-Audiodekodierer, die es Angreifern ermöglicht, den Heap-Speicher zu beschädigen, indem sie ein manipuliertes CAF-Datei mit einem bösartigen bytes_per_packet-Wert bereitstellen. Angreifer können eine CAF-Datei mit überdimensionierten bytes_per_packet und frames_per_packet Werten im desc Chunk erstellen, um einen Ganzzahlarithmetiküberlauf in mace_decode_frame() während der Berechnung der Ausgabemusteranzahl auszulösen. Dies führt zu einer unzureichenden Pufferzuweisung und einem Heap-Schreibzugriff außerhalb des gültigen Bereichs, was die Ausführung von Code ermöglichen könnte.
Metriken
Weakness-Klassen (CWE)
CWE-190Base
Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
cwe.mitre.org →CWE-122Variant
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- Initial Analysis2026-08-07 00:46 UTC· nvd@nist.gov
- CVSS V3.1: AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CPE Configuration: OR *cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:* versions up to (including) 8.1.2
- Reference Type: VulnCheck: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718 Types: Patch
- Reference Type: VulnCheck: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631 Types: Issue Tracking, Patch
- CVE Modified2026-07-29 05:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-66039","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI… → {"id":"CVE-2026-66039","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- CVE Modified2026-07-27 16:18 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-66039","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-07-24 20:18 UTC· disclosure@vulncheck.com
- Affected: FFmpeg
- Description: FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution.
- CVSS V4.0: AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CVSS V3.1: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Betroffene Betriebssysteme
linux
debian / ffmpegtrixie
linux
ubuntu / ffmpegbionic
linux
ubuntu / ffmpegfocal
linux
ubuntu / ffmpegjammy
linux
ubuntu / ffmpegnoble
linux
ubuntu / ffmpegxenial
Quellen & Referenzen
- https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631issue-tracking
- https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718patch
- https://www.vulncheck.com/advisories/ffmpeg-mace6-audio-decoder-heap-out-of-bounds-write-via-caf-filethird-party-advisory
- https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23159
- https://access.redhat.com/security/cve/CVE-2026-8461vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2490308issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-8461.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:43711vendor-advisoryx_refsource_REDHAT
- https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657issue-tracking
- https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951patch
- https://www.vulncheck.com/advisories/ffmpeg-heap-buffer-overflow-via-vobsub-subtitle-demuxerthird-party-advisory
- https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626issue-tracking
- https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8cpatch
- https://www.vulncheck.com/advisories/ffmpeg-lcl-zlib-video-decoder-information-disclosure-via-lcldec-cthird-party-advisory
- https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659issue-tracking
- https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21epatch
- https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decoderthird-party-advisory
- https://access.redhat.com/security/cve/CVE-2026-12706vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2490710issue-trackingx_refsource_REDHAT
- https://lists.ffmpeg.org/archives/list/ffmpeg-devel@ffmpeg.org/message/TTRIJZA7UL6KJTEDMMBGZPLLJERJ3EFX/
Verknüpfte CVEs
- CVE-2026-8461
Ein Schreibzugriff außerhalb des gültigen Bereichs in der MagicYUV-Decoder-Bibliothek von FFmpeg's libavcodec ermöglicht Denial-of-Servic…
highCVSSv3 8.8 - CVE-2026-66038
FFmpeg bis Version 8.1.2 enthält eine Schwachstelle für Informationsleckage im LCL/ZLIB-Videodecoder, die es Angreifern ermöglicht, unini…
highCVSSv3 6.5 - CVE-2026-64835
FFmpeg-Versionen 4.4 bis 8.1.2 enthalten eine Schwachstelle für den Zugriff auf Speicher außerhalb der Grenzen im ADX-Audiodekodierer inn…
highCVSSv3 8.8 - CVE-2026-64832
FFmpeg-Versionen 4.4 bis 8.1.2 enthalten eine doppelte Freigabeschwachstelle im NVIDIA-NVDEC-Hardware-Decoder innerhalb von libavcodec/nv…
highCVSSv3 8.8 - CVE-2026-64830
FFmpeg-Versionen 2.1 bis 8.1.2 enthalten eine Heap-Buffer-Überlauf-Schwachstelle im VobSub-Untertitel-Demultiplexer, die es Angreifern er…
highCVSSv3 8.8 - CVE-2026-12706
Ein Verwendungsfehler nach Freigabe wurde in FFmpeg's RASC-Video-Decoder gefunden.
mediumCVSSv3 6.5