Double-Free Vulnerability in FFmpeg's NVIDIA NVDEC Decoder
CVE-2026-64832

8.7HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-64832?

FFmpeg versions 4.4 through 8.1.2 are affected by a double-free vulnerability within the NVIDIA NVDEC hardware decoder, specifically in the libavcodec/nvdec.c file. This issue can be exploited by attackers who supply crafted video files, leading to potential memory corruption. The vulnerability arises when no decoder surfaces are left, causing an improper memory handling sequence that results in the same frame description data being freed multiple times. Any application that utilizes FFmpeg with NVDEC hardware-accelerated decoding is at risk, necessitating prompt updates to mitigate potential exploits.

Affected Version(s)

FFmpeg 4.4 <= 8.1.2

FFmpeg 4.4 <= 8.1.2

FFmpeg 4c6217477fc64305055b37d9d1d0d76d30e37f97

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pavel Kohout, Aisle Research
.