CVE-2026-64833
HIGHFFmpeg 0.7.1 - 8.1.2 Out-of-Bounds Read via S/PDIF Muxer spdifenc.c
Title source: cnaDescription
FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a core_size value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdif_header_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.
References (3)
Core 3
Core References
Patch patch
Patch Commit
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-read-via-s-pdif-muxer-spdifenc-c
Scores
CVSS v3
7.1
EPSS
0.0021
EPSS Percentile
11.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-125
Status
published
Products (3)
FFmpeg/FFmpeg
0.7.1 - 8.1.2
ffmpeg/ffmpeg
0.7.1 - 8.1.2
FFmpeg/FFmpeg
6f80e2765492700622596af720534cef33dd31b4
Published
Jul 22, 2026
Tracked Since
Jul 22, 2026