{"id":15129,"date":"2026-09-09T15:32:02","date_gmt":"2026-09-09T19:32:02","guid":{"rendered":"https:\/\/advisoryloom.com\/almain\/usn-8716-2-ffmpeg-vulnerabilities\/"},"modified":"2026-09-09T15:32:02","modified_gmt":"2026-09-09T19:32:02","slug":"usn-8716-2-ffmpeg-vulnerabilities","status":"publish","type":"post","link":"https:\/\/ubuntu.com\/security\/notices\/USN-8716-2","title":{"rendered":"USN-8716-2: FFmpeg vulnerabilities"},"content":{"rendered":"<div>USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides<br \/>\nthe corresponding fix for Ubuntu 26.04 LTS.<\/p>\n<p>Original advisory details:<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted media<br \/>\n files in the VobSub subtitle demuxer. An attacker could possibly use<br \/>\n this issue to cause a denial of service or execute arbitrary code.<br \/>\n (CVE-2026-64830)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted HEVC<br \/>\n bitstreams in the Vulkan HEVC hardware decoder. An attacker could<br \/>\n possibly use this issue to cause a denial of service or execute<br \/>\n arbitrary code. (CVE-2026-64831)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted video<br \/>\n files in the NVDEC hardware decoder. An attacker could possibly use<br \/>\n this issue to cause a denial of service or execute arbitrary code.<br \/>\n (CVE-2026-64832)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted DTS<br \/>\n audio streams in the S\/PDIF muxer. An attacker could possibly use this<br \/>\n issue to cause a denial of service or expose sensitive information.<br \/>\n (CVE-2026-64833)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted RTP\/ASF<br \/>\n streams. An attacker could possibly use this issue to cause a denial of<br \/>\n service. (CVE-2026-64834)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted ADX<br \/>\n audio files. An attacker could possibly use this issue to cause a<br \/>\n denial of service or execute arbitrary code. (CVE-2026-64835)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted AVI<br \/>\n files in the TDSC video decoder. An attacker could possibly use this<br \/>\n issue to cause a denial of service or execute arbitrary code.<br \/>\n (CVE-2026-65703)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted<br \/>\n ffconcat files processed via the TY demuxer. An attacker could possibly<br \/>\n use this issue to cause a denial of service or execute arbitrary code.<br \/>\n (CVE-2026-65704)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted video<br \/>\n streams in the vf_floodfill video filter. An attacker could possibly<br \/>\n use this issue to cause a denial of service or execute arbitrary code.<br \/>\n (CVE-2026-65705)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted NV12<br \/>\n video frames in the vf_swaprect video filter. An attacker could<br \/>\n possibly use this issue to cause a denial of service or execute<br \/>\n arbitrary code. (CVE-2026-65706)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted hvcC<br \/>\n NAL arrays in the HEVC parser. An attacker could possibly use this<br \/>\n issue to cause a denial of service or execute arbitrary code.<br \/>\n (CVE-2026-75141)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted MPEG<br \/>\n system headers. An attacker could possibly use this issue to cause a<br \/>\n denial of service or execute arbitrary code. (CVE-2026-75142)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted<br \/>\n network input in the librist protocol handler. An attacker could<br \/>\n possibly use this issue to cause a denial of service or execute<br \/>\n arbitrary code. (CVE-2026-75143)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted Dirac<br \/>\n data units in the VC2 HQ RTP packetizer. An attacker could possibly use<br \/>\n this issue to cause a denial of service or execute arbitrary code.<br \/>\n (CVE-2026-75144)<\/p>\n<p> It was discovered that FFmpeg incorrectly handled certain crafted DASH<br \/>\n manifests. An attacker could possibly use this issue to cause a denial<br \/>\n of service or expose sensitive information. (CVE-2026-75146)<\/p><\/div>\n","protected":false},"excerpt":{"rendered":"<p>USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides the corresponding fix for Ubuntu 26.04 LTS. Original advisory<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27,6],"tags":[29,28],"class_list":["post-15129","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-linux-advisories","category-vendor-advisories","tag-advisories","tag-linux"],"_links":{"self":[{"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/posts\/15129","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/comments?post=15129"}],"version-history":[{"count":0,"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/posts\/15129\/revisions"}],"wp:attachment":[{"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/media?parent=15129"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/categories?post=15129"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/advisoryloom.com\/almain\/wp-json\/wp\/v2\/tags?post=15129"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}