High severity8.8NVD Advisory· Published Jul 24, 2026· Updated Aug 7, 2026
CVE-2026-66036
CVE-2026-66036
Description
FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to corrupt heap memory by supplying a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the -reinit_filter 0 option. Attackers can provide a malicious video input where vf_hqdn3d.config_input() allocates undersized per-plane line-history buffers based on the initial frame width, and subsequent larger frames cause denoise_spatial() to write beyond the allocation boundary, resulting in heap memory corruption.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- osv-coords3 versionspkg:rpm/opensuse/ffmpeg-4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-9&distro=openSUSE%20Tumbleweed
< 4.4.8-4.1+ 2 more
- (no CPE)range: < 4.4.8-4.1
- (no CPE)range: < 7.1.5-2.1
- (no CPE)range: < 9.0.1-2.1
Patches
Vulnerability mechanics
References
3- code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4cnvdPatch
- code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783nvdIssue TrackingPatch
- www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-vf-hqdn3d-filternvdThird Party Advisory
News mentions
2- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026
- Multiple FFmpeg Vulnerabilities Allow Attackers to Corrupt Memory Via Malicious Video FileCyber Security News · Jul 28, 2026