USN-8716-2: FFmpeg vulnerabilities
USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides the corresponding fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64830) It was discovered that FFmpeg incorrectly handled certain crafted HEVC bitstreams in the Vulkan HEVC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64831) It was discovered that FFmpeg incorrectly handled certain crafted video files in the NVDEC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64832) It was discovered that FFmpeg incorrectly handled certain crafted DTS audio streams in the S/PDIF muxer. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2026-64833) It was discovered that FFmpeg incorrectly handled certain crafted RTP/ASF streams. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-64834) It was discovered that FFmpeg incorrectly handled certain crafted ADX audio files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64835) It was discovered that FFmpeg incorrectly handled certain crafted AVI files in the TDSC video decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65703) It was discovered that FFmpeg incorrectly handled certain crafted ffconcat files processed via the TY demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65704) It was discovered that FFmpeg incorrectly handled certain crafted video streams in the vf_floodfill video filter. An attacker could p
Details
Original advisory: https://ubuntu.com/security/notices/USN-8716-2
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-648300.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-648310.85% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 56% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-648320.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-648330.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-648340.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-648350.33% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 26% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-657030.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-657040.18% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-657050.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-657060.19% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 8% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-64830 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64831 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64832 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64833 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64834 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-64835 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65703 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65704 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65705 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-65706 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75141 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75142 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75143 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75144 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-75146 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [mittel] ffmpeg: Mehrere Schwachstellen ermöglichen Codeausführung und DoScert-bund
- high[UPDATE] [hoch] ffmpeg: Mehrere Schwachstellencert-bund
- high[UPDATE] [hoch] ffmpeg: Mehrere Schwachstellencert-bund
- unknownUSN-8716-1: FFmpeg vulnerabilitiesubuntu
- highCVE-2026-75146: FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/d…nvd
- highCVE-2026-75144: FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac R…nvd
- criticalCVE-2026-75143: FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (liba…nvd
- highCVE-2026-75142: FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavforma…nvd
- highCVE-2026-75141: FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writ…nvd
- highCVE-2026-65706: FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swapr…nvd
- highCVE-2026-65705: FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_flood…nvd
- highCVE-2026-65704: FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to ca…nvd
More from Ubuntu Security Notices
- unknownUSN-8747-1: Beets vulnerability2026-09-10
- unknownUSN-8746-1: libEBML vulnerability2026-09-10
- unknownUSN-8745-1: KissFFT vulnerabilities2026-09-10
- unknownUSN-8748-1: Linux kernel (NVIDIA) vulnerabilities2026-09-10
- unknownUSN-8744-1: Python vulnerabilities2026-09-10