Heap Buffer Overflow Vulnerability in FFmpeg VobSub Demuxer
CVE-2026-64830
8.7HIGH
What is CVE-2026-64830?
FFmpeg versions 2.1 through 8.1.2 are susceptible to a heap buffer overflow in the VobSub subtitle demuxer. This flaw can be exploited by attackers who provide a crafted .sub/.idx subtitle file that claims more distinct stream IDs than the bounds of a fixed-size array. This condition leads to the potential for unbounded writes beyond the designated memory boundary, exposing applications utilizing the VobSub demuxer to the risk of arbitrary code execution.
Affected Version(s)
FFmpeg 2.1 <= 8.1.2
FFmpeg 2.1 <= 8.1.2
FFmpeg dbd495f066a85ba96b17433f4306582aa37c3951
