USN-8716-2
Dashboard / Vulnerabilities / USN-8716-2
USN-8716-2
Summary: ffmpeg vulnerabilities
Details: USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides the corresponding fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64830) It was discovered that FFmpeg incorrectly handled certain crafted HEVC bitstreams in the Vulkan HEVC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64831) It was discovered that FFmpeg incorrectly handled certain crafted video files in the NVDEC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64832) It was discovered that FFmpeg incorrectly handled certain crafted DTS audio streams in the S/PDIF muxer. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2026-64833) It was discovered that FFmpeg incorrectly handled certain crafted RTP/ASF streams. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-64834) It was discovered that FFmpeg incorrectly handled certain crafted ADX audio files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64835) It was discovered that FFmpeg incorrectly handled certain crafted AVI files in the TDSC video decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65703) It was discovered that FFmpeg incorrectly handled certain crafted ffconcat files processed via the TY demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65704) It was discovered that FFmpeg incorrectly handled certain crafted video streams in the vf_floodfill video filter. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65705) It was discovered that FFmpeg incorrectly handled certain crafted NV12 video frames in the vf_swaprect video filter. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65706) It was discovered that FFmpeg incorrectly handled certain crafted hvcC NAL arrays in the HEVC parser. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75141) It was discovered that FFmpeg incorrectly handled certain crafted MPEG system headers. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75142) It was discovered that FFmpeg incorrectly handled certain crafted network input in the librist protocol handler. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75143) It was discovered that FFmpeg incorrectly handled certain crafted Dirac data units in the VC2 HQ RTP packetizer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75144) It was discovered that FFmpeg incorrectly handled certain crafted DASH manifests. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2026-75146)
References: https://ubuntu.com/security/notices/USN-8716-2, https://ubuntu.com/security/CVE-2026-64830, https://ubuntu.com/security/CVE-2026-64831, https://ubuntu.com/security/CVE-2026-64832, https://ubuntu.com/security/CVE-2026-64833, https://ubuntu.com/security/CVE-2026-64834, https://ubuntu.com/security/CVE-2026-64835, https://ubuntu.com/security/CVE-2026-65703, https://ubuntu.com/security/CVE-2026-65704, https://ubuntu.com/security/CVE-2026-65705, https://ubuntu.com/security/CVE-2026-65706, https://ubuntu.com/security/CVE-2026-75141, https://ubuntu.com/security/CVE-2026-75142, https://ubuntu.com/security/CVE-2026-75143, https://ubuntu.com/security/CVE-2026-75144, https://ubuntu.com/security/CVE-2026-75146
Affected packages
Package
Name: ffmpeg
Purl: pkg:deb/ubuntu/ffmpeg?arch=source&distro=esm-apps%2Fresolute
Affected ranges
Type: ECOSYSTEM
Events:
