USN-8716-2

    Dashboard / Vulnerabilities / USN-8716-2

    USN-8716-2

    Published: 9 Sept 2026Last Modified: 10 Sept 2026

    Summary: ffmpeg vulnerabilities

    Details: USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides the corresponding fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64830) It was discovered that FFmpeg incorrectly handled certain crafted HEVC bitstreams in the Vulkan HEVC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64831) It was discovered that FFmpeg incorrectly handled certain crafted video files in the NVDEC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64832) It was discovered that FFmpeg incorrectly handled certain crafted DTS audio streams in the S/PDIF muxer. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2026-64833) It was discovered that FFmpeg incorrectly handled certain crafted RTP/ASF streams. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-64834) It was discovered that FFmpeg incorrectly handled certain crafted ADX audio files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64835) It was discovered that FFmpeg incorrectly handled certain crafted AVI files in the TDSC video decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65703) It was discovered that FFmpeg incorrectly handled certain crafted ffconcat files processed via the TY demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65704) It was discovered that FFmpeg incorrectly handled certain crafted video streams in the vf_floodfill video filter. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65705) It was discovered that FFmpeg incorrectly handled certain crafted NV12 video frames in the vf_swaprect video filter. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65706) It was discovered that FFmpeg incorrectly handled certain crafted hvcC NAL arrays in the HEVC parser. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75141) It was discovered that FFmpeg incorrectly handled certain crafted MPEG system headers. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75142) It was discovered that FFmpeg incorrectly handled certain crafted network input in the librist protocol handler. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75143) It was discovered that FFmpeg incorrectly handled certain crafted Dirac data units in the VC2 HQ RTP packetizer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75144) It was discovered that FFmpeg incorrectly handled certain crafted DASH manifests. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2026-75146)

    Affected packages

    Package

    Name: ffmpeg

    Purl: pkg:deb/ubuntu/ffmpeg?arch=source&distro=esm-apps%2Fresolute

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -7:8.0.1-3ubuntu2+esm4

    Affected versions

    7:7.1.1-1ubuntu4
    7:7.1.2-1ubuntu3
    7:7.1.2-1ubuntu4
    7:7.1.3-1ubuntu1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-8716-2 | CVE-DB