High severity7.8NVD Advisory· Published Aug 6, 2026· Updated Sep 1, 2026
CVE-2026-70632
CVE-2026-70632
Description
FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- osv-coords4 versionspkg:rpm/opensuse/ffmpeg-4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-8&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/ffmpeg-9&distro=openSUSE%20Tumbleweed
< 4.4.8-5.1+ 3 more
- (no CPE)range: < 4.4.8-5.1
- (no CPE)range: < 7.1.5-2.1
- (no CPE)range: < 8.1.2-3.1
- (no CPE)range: < 9.0.1-3.1
Patches
Vulnerability mechanics
References
5- code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111envdPatch
- code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9nvdPatch
- code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087nvdPatch
- code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898nvdIssue TrackingPatch
- www.vulncheck.com/advisories/ffmpeg-heap-out-of-bounds-write-in-cfhd-decoder-via-avi-demuxingnvdPatchThird Party Advisory
News mentions
1- FFmpeg: Five Vulnerabilities Disclosed, Two High Severity Heap Corruption FlawsVypr Intelligence · Aug 6, 2026