ZeroHour
Ubuntu Security Noticespublished ()ingested
Part of a story covered by 13 sources: “Ubuntu patches nine advisories across Perl, FFmpeg, .NET, Netty, glibc, PHP, Python, Beets and Apache, then refreshes 24.04.5 LTS install media” — merged summary and timeline →

USN-8716-2: FFmpeg vulnerabilities

AI summary · glm-5.3-flash

Ubuntu issued USN-8716-2 fixing FFmpeg VobSub, Vulkan HEVC, and NVDEC decoder flaws that could allow denial of service or code execution.

USN-8716-2 provides the Ubuntu 26.04 LTS counterpart to the FFmpeg fixes in USN-8716-1. Crafted media files could cause denial of service or arbitrary code execution through the VobSub subtitle demuxer (CVE-2026-64830), the Vulkan HEVC hardware decoder (CVE-2026-64831), and the NVDEC video decoder path.

  • Extends USN-8716-1 FFmpeg fixes to Ubuntu 26.04 LTS
  • CVE-2026-64830: crafted VobSub files can crash FFmpeg or execute code
  • CVE-2026-64831: crafted HEVC bitstreams trigger Vulkan decoder flaws
  • NVDEC decoder flaw also addressed with DoS or code-execution impact
VendorsCanonical
ProductsFFmpegUbuntu
OrganizationsCanonical

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-64831
+1 in the same advisory: …64830
FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite r

FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.

NVD description · AI analysis pending
8.7<1%
  • ffmpeg ffmpeg
Full article

USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides the corresponding fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64830) It was discovered that FFmpeg incorrectly handled certain crafted HEVC bitstreams in the Vulkan HEVC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64831) It was discovered that FFmpeg incorrectly handled certain crafted video files in the NVDEC…

This source does not provide full text. Read it at ubuntu.com.