High severity7.8NVD Advisory· Published Aug 6, 2026· Updated Sep 1, 2026
CVE-2026-70628
CVE-2026-70628
Description
FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords4 versionspkg:rpm/opensuse/ffmpeg-4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-8&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-9&distro=openSUSE%20Tumbleweed
< 4.4.8-5.1+ 3 more
- (no CPE)range: < 4.4.8-5.1
- (no CPE)range: < 7.1.5-2.1
- (no CPE)range: < 8.1.2-3.1
- (no CPE)range: < 9.0.1-3.1
Patches
Vulnerability mechanics
References
5- code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506nvdPatch
- code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30nvdPatch
- code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7cnvdPatch
- code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897nvdIssue TrackingPatch
- www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-filenvdPatchThird Party Advisory
News mentions
1- FFmpeg: Five Vulnerabilities Disclosed, Two High Severity Heap Corruption FlawsVypr Intelligence · Aug 6, 2026