USN-8716-2: FFmpeg vulnerabilities
Ubuntu issued USN-8716-2 fixing FFmpeg VobSub, Vulkan HEVC, and NVDEC decoder flaws that could allow denial of service or code execution.
USN-8716-2 provides the Ubuntu 26.04 LTS counterpart to the FFmpeg fixes in USN-8716-1. Crafted media files could cause denial of service or arbitrary code execution through the VobSub subtitle demuxer (CVE-2026-64830), the Vulkan HEVC hardware decoder (CVE-2026-64831), and the NVDEC video decoder path.
- Extends USN-8716-1 FFmpeg fixes to Ubuntu 26.04 LTS
- CVE-2026-64830: crafted VobSub files can crash FFmpeg or execute code
- CVE-2026-64831: crafted HEVC bitstreams trigger Vulkan decoder flaws
- NVDEC decoder flaw also addressed with DoS or code-execution impact
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-64831 +1 in the same advisory: …64830 | FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite r FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution. NVD description · AI analysis pending | 8.7 | <1% |
| — |
USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides the corresponding fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64830) It was discovered that FFmpeg incorrectly handled certain crafted HEVC bitstreams in the Vulkan HEVC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64831) It was discovered that FFmpeg incorrectly handled certain crafted video files in the NVDEC…
This source does not provide full text. Read it at ubuntu.com.