PT-2026-63435 · FFmpeg · Ffmpeg
CVE-2026-64831
·
Publicado
2026-07-22
·
Atualizado
2026-07-22
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps num hrd parameters value exceeding HEVC MAX SUB LAYERS in any supported container format to overflow stack-allocated arrays in the vk hevc end frame function, potentially achieving arbitrary code execution.
Correção
Stack Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Ffmpeg