PT-2026-64412 · FFmpeg · Ffmpeg

·

CVE-2026-66036

·

Published

2026-07-24

·

Updated

2026-07-24

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit filter 0 option. Attackers can provide a malicious video input where vf hqdn3d.config input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise spatial() to write beyond the allocation boundary, resulting in heap memory corruption.

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66036

Affected Products

Ffmpeg