CVE-2026-65704

Summary

FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat file processed with the -safe 0 flag. The TY demuxer's demux_audio() function decrements packet size without bounds checking, producing a negative size value that is passed to memcpy() in shorten_decode_frame(), where conversion to size_t wraps the value to near SIZE_MAX and triggers reads beyond the source allocation and writes far beyond the Shorten decoder's bitstream buffer.

Affected Software

VendorProductVersion RangeStatus
FFmpegFFmpeg0 <= 8.1.2affected
FFmpegFFmpegde771bd52774a52d45b0e2c82e56995a1ef40df7unaffected

Weaknesses

  • CWE-787: Out-of-bounds Write
  • CWE-191: Integer Underflow (Wrap or Wraparound)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References