High severity8.8NVD Advisory· Published Jul 22, 2026· Updated Jul 28, 2026
CVE-2026-64832
CVE-2026-64832
Description
FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12- osv-coords10 versionspkg:apk/chainguard/ffmpeg-6pkg:apk/chainguard/ffmpeg-7.1pkg:apk/chainguard/ffmpeg-8.0pkg:apk/chainguard/ffmpeg-8.1pkg:apk/wolfi/ffmpeg-7.1pkg:apk/wolfi/ffmpeg-8.0pkg:apk/wolfi/ffmpeg-8.1pkg:rpm/opensuse/ffmpeg-4&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/ffmpeg-4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Leap%2016.0
< 0+ 9 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 4.4.7-bp160.3.1
- (no CPE)range: < 4.4.8-3.1
- (no CPE)range: < 7.1.4-160000.3.1
Patches
Vulnerability mechanics
References
3- code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97nvdPatch
- code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664nvdIssue TrackingPatch
- www.vulncheck.com/advisories/ffmpeg-double-free-in-nvdec-hardware-decoder-via-nvdec-cnvdThird Party Advisory
News mentions
0No linked articles in our index yet.