Double-Free Vulnerability in FFmpeg's NVIDIA NVDEC Decoder
CVE-2026-64832
8.7HIGH
What is CVE-2026-64832?
FFmpeg versions 4.4 through 8.1.2 are affected by a double-free vulnerability within the NVIDIA NVDEC hardware decoder, specifically in the libavcodec/nvdec.c file. This issue can be exploited by attackers who supply crafted video files, leading to potential memory corruption. The vulnerability arises when no decoder surfaces are left, causing an improper memory handling sequence that results in the same frame description data being freed multiple times. Any application that utilizes FFmpeg with NVDEC hardware-accelerated decoding is at risk, necessitating prompt updates to mitigate potential exploits.
Affected Version(s)
FFmpeg 4.4 <= 8.1.2
FFmpeg 4.4 <= 8.1.2
FFmpeg 4c6217477fc64305055b37d9d1d0d76d30e37f97
