Logo
vulnerabilityCVE-2026-64833
Name
CVE-2026-64833
Source
NVD ( link)Debian ( link)
Description
FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ffmpeg
Exploitable

Vulnerability Ratings#


7.1
CVSSv4
7.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.1.5
Exploitable
buildroot
master
6.1.5
Exploitable
openwrt
openwrt-25.12
6.1.4-r1
Exploitable
yocto
kirkstone
5.0.3
Exploitable
yocto
master
8.1.2
Exploitable
yocto
scarthgap
6.1.4
Exploitable