High severity7.8NVD Advisory· Published Jul 23, 2026· Updated Aug 7, 2026
CVE-2026-65703
CVE-2026-65703
Description
FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap corruption by supplying a crafted AVI file that changes frame dimensions across TDSF frames. The tdsc_parse_tdsf() function fails to unreference the existing reference frame before calling av_frame_get_buffer(), causing tdsc_blit() and tdsc_yuv2rgb() to write attacker-controlled pixel data beyond the end of the undersized reference frame buffer, resulting in a process crash and potential code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- osv-coords3 versionspkg:rpm/opensuse/ffmpeg-4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-9&distro=openSUSE%20Tumbleweed
< 4.4.8-4.1+ 2 more
- (no CPE)range: < 4.4.8-4.1
- (no CPE)range: < 7.1.5-2.1
- (no CPE)range: < 9.0.1-2.1
Patches
Vulnerability mechanics
References
3- code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200cnvdPatch
- code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773nvdIssue TrackingPatch
- www.vulncheck.com/advisories/ffmpeg-out-of-bounds-write-in-tdsc-video-decodernvdThird Party Advisory
News mentions
0No linked articles in our index yet.