Logo
vulnerabilityCVE-2026-65704
Name
CVE-2026-65704
Source
NVD ( link)Debian ( link)
Description
FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
ffmpeg
Exploitable

Vulnerability Ratings#


7.3
CVSSv4
7.8
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
6.1.5
Exploitable
buildroot
master
6.1.5
Exploitable
openwrt
master
6.1.4-r2
Exploitable
openwrt
openwrt-25.12
6.1.4-r1
Exploitable
yocto
master
8.1.2
Exploitable
yocto
scarthgap
6.1.4
Exploitable