CVE-2026-64832
HIGHFFmpeg 4.4 - 8.1.2 Double-Free in NVDEC Hardware Decoder via nvdec.c
Title source: cnaDescription
FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.
References (3)
Core 3
Core References
Patch patch
Patch Commit
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-c
Scores
CVSS v3
8.8
EPSS
0.0033
EPSS Percentile
25.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-415
Status
published
Products (3)
FFmpeg/FFmpeg
4.4 - 8.1.2
ffmpeg/ffmpeg
4.4 - 8.1.2
FFmpeg/FFmpeg
4c6217477fc64305055b37d9d1d0d76d30e37f97
Published
Jul 22, 2026
Tracked Since
Jul 22, 2026