High severity8.8NVD Advisory· Published Jul 24, 2026· Updated Aug 7, 2026
CVE-2026-66041
CVE-2026-66041
Description
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
10- osv-coords8 versionspkg:apk/chainguard/ffmpeg-7.1pkg:apk/chainguard/ffmpeg-8.0pkg:apk/chainguard/ffmpeg-8.1pkg:apk/wolfi/ffmpeg-7.1pkg:apk/wolfi/ffmpeg-8.0pkg:apk/wolfi/ffmpeg-8.1pkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Tumbleweed
< 0+ 7 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 7.1.4-160000.3.1
- (no CPE)range: < 7.1.5-2.1
Patches
Vulnerability mechanics
References
3News mentions
3- ⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS HijacksThe Hacker News · Aug 3, 2026
- Multiple FFmpeg Vulnerabilities Allow Attackers to Corrupt Memory Via Malicious Video FileCyber Security News · Jul 28, 2026
- FFmpeg: Four Memory Corruption Vulnerabilities Disclosed in BatchVypr Intelligence · Jul 25, 2026