High severity8.8NVD Advisory· Published Jul 22, 2026· Updated Jul 28, 2026
CVE-2026-64835
CVE-2026-64835
Description
FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- osv-coords3 versionspkg:rpm/opensuse/ffmpeg-4&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/ffmpeg-4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Leap%2016.0
< 4.4.7-bp160.3.1+ 2 more
- (no CPE)range: < 4.4.7-bp160.3.1
- (no CPE)range: < 4.4.8-3.1
- (no CPE)range: < 7.1.4-160000.3.1
Patches
Vulnerability mechanics
References
3- code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21envdPatch
- code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659nvdIssue TrackingPatch
- www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-audio-decodernvdThird Party Advisory
News mentions
0No linked articles in our index yet.