← Back to blog

FFmpeg Vulnerabilities Expose Ubuntu Systems to Remote Attacks

Multiple high-severity flaws in FFmpeg affect Ubuntu systems, potentially allowing remote code execution and denial of service.

TL;DR

  • Several FFmpeg vulnerabilities impact Ubuntu 26.04 LTS and earlier versions.
  • Flaws allow denial of service, arbitrary code execution, and sensitive data exposure.
  • Affected components include VobSub, HEVC, NVDEC decoders, S/PDIF muxer, and more.
  • Patches released in Ubuntu Security Notices USN-8716-2 and USN-8738-1.
  • Organizations should update FFmpeg packages immediately.

Recent security updates address multiple vulnerabilities in FFmpeg impacting Ubuntu systems. These flaws span various multimedia processing components and may allow attackers to execute arbitrary code or cause denial of service.

The issues affect core decoding and parsing functions used across numerous media formats. Organizations running Ubuntu are advised to apply the latest patches to mitigate potential exploitation.

Core Vulnerabilities

  • VobSub subtitle demuxer mishandles crafted files leading to code execution or DoS (CVE-2026-64830)
  • HEVC bitstreams trigger memory corruption in Vulkan hardware decoder (CVE-2026-64831)
  • NVDEC hardware decoder fails to validate malicious video inputs properly (CVE-2026-64832)
  • S/PDIF muxer exposes sensitive information when processing malformed DTS audio streams (CVE-2026-64833)

Additional Processing Flaws

  • hqdn3d filter crashes or executes code via specially crafted video frames (CVE-2026-66036)
  • Compressed video file handling leaks sensitive data through improper validation (CVE-2026-66038)
  • Audio file parsing allows crashes or remote code execution (CVE-2026-66039)
  • Subtitle and general video file processing contain exploitable memory flaws (CVE-2026-70628, CVE-2026-70632)

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.