Heap Buffer Overflow Vulnerability in FFmpeg VobSub Demuxer
CVE-2026-64830

8.7HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-64830?

FFmpeg versions 2.1 through 8.1.2 are susceptible to a heap buffer overflow in the VobSub subtitle demuxer. This flaw can be exploited by attackers who provide a crafted .sub/.idx subtitle file that claims more distinct stream IDs than the bounds of a fixed-size array. This condition leads to the potential for unbounded writes beyond the designated memory boundary, exposing applications utilizing the VobSub demuxer to the risk of arbitrary code execution.

Affected Version(s)

FFmpeg 2.1 <= 8.1.2

FFmpeg 2.1 <= 8.1.2

FFmpeg dbd495f066a85ba96b17433f4306582aa37c3951

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pavel Kohout, Aisle Research
.