Logo
vulnerabilityCVE-2026-66036
Name
CVE-2026-66036
Source
NVD ( link)Debian ( link)
Description
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ffmpeg
Exploitable

Vulnerability Ratings#


7.7
CVSSv4
8.8
CVSSv31
8.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
master
6.1.5
Exploitable
openwrt
master
6.1.4-r2
Exploitable
openwrt
openwrt-25.12
6.1.4-r1
Exploitable
yocto
kirkstone
5.0.3
Exploitable
yocto
master
8.1.2
Exploitable
yocto
scarthgap
6.1.4
Exploitable