Logo
vulnerabilityCVE-2026-64832
Name
CVE-2026-64832
Source
NVD ( link)Debian ( link)
Description
FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ffmpeg
Exploitable

Vulnerability Ratings#


8.7
CVSSv4
8.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.1.5
Exploitable
buildroot
master
6.1.5
Exploitable
openwrt
master
6.1.4-r2
Exploitable
yocto
kirkstone
5.0.3
Exploitable
yocto
master
8.1.2
Exploitable
yocto
scarthgap
6.1.4
Exploitable