USN-8716-1: FFmpeg vulnerabilities
It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64830) It was discovered that FFmpeg incorrectly handled certain crafted DTS audio streams in the S/PDIF muxer. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2026-64833) It was discovered that FFmpeg incorrectly handled certain crafted RTP/ASF streams. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-64834) It was discovered that FFmpeg incorrectly handled certain crafted ADX audio files. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-64835) It was discovered that FFmpeg incorrectly handled certain crafted AVI files in the TDSC video decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65703) It was discovered that FFmpeg incorrectly handled certain crafted ffconcat files processed via the TY demuxer. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-65704) It was discovered that FFmpeg incorrectly handled certain crafted video streams in the vf_floodfill video filter. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-65705) It was discovered that FFmpeg incorrectly handled certain crafted NV12 video frames in the vf_swaprect video filter. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-65706) It was discovered that FFmpeg incorrectly handled certain crafted hvcC NAL arrays in the HEVC parser. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75141) It was discovered that FFmpeg incorrectly handled certain crafted MPEG system headers. An attacker c
CSIRTS triage
- What
- Multiple vulnerabilities in VobSub subtitle demuxer, S/PDIF muxer, RTP/ASF streams, ADX audio files, and TDSC video decoder allow code execution, denial of service, or information disclosure.
- Who is affected
- FFmpeg users on Ubuntu 22.04 LTS, Ubuntu 24.04 LTS, and other distributions processing crafted media files.
- Urgency
- Unknown severity; multiple issues affect different codecs and demuxers requiring individual assessment.
- Action
- Consult the FFmpeg security advisories and apply vendor patches for the specific CVEs affecting your deployed version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch FFmpeg
Get an email when a new FFmpeg advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8716-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-648300.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-648330.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-648340.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-648350.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-657030.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-657040.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-657050.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-657060.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751410.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-751420.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-64830 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64833 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64834 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64835 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65703 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65704 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65705 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65706 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75141 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75142 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75143 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75144 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75146 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [mittel] ffmpeg: Mehrere Schwachstellen ermöglichen Codeausführung und DoScert-bund
- high[UPDATE] [hoch] ffmpeg: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] ffmpeg: Mehrere Schwachstellencert-bund
- unknownUSN-8716-2: FFmpeg vulnerabilitiesubuntu
- highCVE-2026-75146: FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/d…nvd
- highCVE-2026-75144: FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac R…nvd
- criticalCVE-2026-75143: FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (liba…nvd
- highCVE-2026-75142: FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavforma…nvd
- highCVE-2026-75141: FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writ…nvd
- highCVE-2026-65706: FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swapr…nvd
- highCVE-2026-65705: FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_flood…nvd
- highCVE-2026-65704: FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to ca…nvd
More from Ubuntu Security Notices
- unknownUSN-8747-1: Beets vulnerability2026-09-10
- unknownUSN-8746-1: libEBML vulnerability2026-09-10
- unknownUSN-8745-1: KissFFT vulnerabilities2026-09-10
- unknownUSN-8748-1: Linux kernel (NVIDIA) vulnerabilities2026-09-10
- unknownUSN-8744-1: Python vulnerabilities2026-09-10