๐Ÿ” CVE Alert

CVE-2026-64831

HIGH 8.8

FFmpeg 8.0 - 8.1.2 Stack Buffer Overflow in Vulkan HEVC Decoder

CVSS Score
8.8
EPSS Score
0.0%
EPSS Percentile
0th

FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vps_num_hrd_parameters value exceeding HEVC_MAX_SUB_LAYERS in any supported container format to overflow stack-allocated arrays in the vk_hevc_end_frame function, potentially achieving arbitrary code execution.

CWE CWE-121
Vendor ffmpeg
Product ffmpeg
Published Jul 22, 2026
Stay Ahead of the Next One

Get instant alerts for ffmpeg ffmpeg

Be the first to know when new high vulnerabilities affecting ffmpeg ffmpeg are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

FFmpeg / FFmpeg
8.0 โ‰ค 8.1.2 92737390dc133daadce47dd7d2ec8ef3d9ebcbed

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665 code.ffmpeg.org: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed vulncheck.com: https://www.vulncheck.com/advisories/ffmpeg-stack-buffer-overflow-in-vulkan-hevc-decoder

Credits

Pavel Kohout, Aisle Research