Stack Buffer Overflow in FFmpeg's Vulkan HEVC Decoder
CVE-2026-64831

8.7HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-64831?

A stack buffer overflow vulnerability exists in FFmpeg versions 8.0 through 8.1.2, specifically within the Vulkan HEVC hardware decoder. This flaw allows remote attackers to manipulate the return addresses and adjacent stack frames. By supplying a specially crafted HEVC/H.265 bitstream that exceeds the limit of HEVC_MAX_SUB_LAYERS with a malicious vps_num_hrd_parameters value, attackers can overflow stack-allocated arrays in the vk_hevc_end_frame function. This can potentially lead to arbitrary code execution vulnerabilities, compromising the integrity of the system.

Affected Version(s)

FFmpeg 8.0 <= 8.1.2

FFmpeg 8.0 <= 8.1.2

FFmpeg 92737390dc133daadce47dd7d2ec8ef3d9ebcbed

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pavel Kohout, Aisle Research
.