{"schema_version":"1.7.2","id":"OESA-2026-3082","modified":"2026-08-06T11:11:58Z","published":"2026-07-19T11:11:58Z","upstream":["CVE-2023-6602","CVE-2025-0518","CVE-2025-10256","CVE-2025-12343","CVE-2025-1594","CVE-2026-30999","CVE-2026-40962","CVE-2026-6385"],"summary":"ffmpeg security update","details":"FFmpeg is a complete and free Internet live audio and video broadcasting solution for Linux/Unix. It also includes a digital VCR. It can encode in real time in many formats including MPEG1 audio and video, MPEG4, h263, ac3, asf, avi, real, mjpeg, and flash.\r\n\r\nSecurity Fix(es):\n\nA flaw was found in FFmpeg s TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists.(CVE-2023-6602)\n\nUnchecked Return Value, Out-of-bounds Read vulnerability in FFmpeg allows Read Sensitive Constants Within an Executable. This vulnerability is associated with program files  https://github.Com/FFmpeg/FFmpeg/blob/master/libavfilter/af_pan.C .\n\nThis issue affects FFmpeg: 7.1.\n\nIssue was fixed:  https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a\n\n https://github.com/FFmpeg/FFmpeg/commit/b5b6391d64807578ab872dc58fb8aa621dcfc38a This issue was discovered by: Simcha Kosman(CVE-2025-0518)\n\nA NULL pointer dereference vulnerability exists in FFmpeg’s Firequalizer filter (libavfilter/af_firequalizer.c) due to a missing check on the return value of av_malloc_array() in the config_input() function. An attacker could exploit this by tricking a victim into processing a crafted media file with the Firequalizer filter enabled, causing the application to dereference a NULL pointer and crash, leading to denial of service.(CVE-2025-10256)\n\nA flaw was found in FFmpeg’s TensorFlow backend within the libavfilter/dnn_backend_tf.c source file. The issue occurs in the dnn_execute_model_tf() function, where a task object is freed multiple times in certain error-handling paths. This redundant memory deallocation can lead to a double-free condition, potentially causing FFmpeg or any application using it to crash when processing TensorFlow-based DNN models. This results in a denial-of-service scenario but does not allow arbitrary code execution under normal conditions.(CVE-2025-12343)\n\nA vulnerability, which was classified as critical, was found in FFmpeg up to 7.1. This affects the function ff_aac_search_for_tns of the file libavcodec/aacenc_tns.c of the component AAC Encoder. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.(CVE-2025-1594)\n\nA heap buffer overflow in the av_bprint_finalize() function of FFmpeg v8.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input.(CVE-2026-30999)\n\nFFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.(CVE-2026-40962)\n\nA flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser&apos;s fragment reassembly bounds checks, leading to a heap out-of-bounds write. Successful exploitation can result in a denial of service (DoS) due to an application crash, and potentially lead to arbitrary code execution.(CVE-2026-6385)","affected":[{"package":{"ecosystem":"openEuler:24.03-LTS-SP3","name":"ffmpeg","purl":"pkg:rpm/openEuler/ffmpeg&distro=openEuler-24.03-LTS-SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.1-35.oe2403sp3"}]}],"ecosystem_specific":{"aarch64":["ffmpeg-6.1.1-35.oe2403sp3.aarch64.rpm","ffmpeg-debuginfo-6.1.1-35.oe2403sp3.aarch64.rpm","ffmpeg-debugsource-6.1.1-35.oe2403sp3.aarch64.rpm","ffmpeg-devel-6.1.1-35.oe2403sp3.aarch64.rpm","ffmpeg-libs-6.1.1-35.oe2403sp3.aarch64.rpm","libavdevice-6.1.1-35.oe2403sp3.aarch64.rpm"],"src":["ffmpeg-6.1.1-35.oe2403sp3.src.rpm"],"x86_64":["ffmpeg-6.1.1-35.oe2403sp3.x86_64.rpm","ffmpeg-debuginfo-6.1.1-35.oe2403sp3.x86_64.rpm","ffmpeg-debugsource-6.1.1-35.oe2403sp3.x86_64.rpm","ffmpeg-devel-6.1.1-35.oe2403sp3.x86_64.rpm","ffmpeg-libs-6.1.1-35.oe2403sp3.x86_64.rpm","libavdevice-6.1.1-35.oe2403sp3.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-3082"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-6602"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-0518"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-10256"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-12343"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-1594"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-30999"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40962"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6385"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}],"database_specific":{"severity":"Critical"}}
