Out-of-Bounds Read in FFmpeg S/PDIF Muxer
CVE-2026-64833

7.1HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-64833?

FFmpeg versions 0.7.1 through 8.1.2 are susceptible to an out-of-bounds read vulnerability found in the S/PDIF muxer. Attackers can exploit this by sending a specially crafted DTS stream with a core_size value exceeding the actual packet length. This vulnerability originates from a lack of proper bounds checking in the spdif_header_dts4 function. During the remuxing of S/PDIF streams, a malicious DTS-HD audio stream can trigger unauthorized memory read accesses that extend beyond the designated buffer, leading to potential data leaks and system compromise.

Affected Version(s)

FFmpeg 0.7.1 <= 8.1.2

FFmpeg 0.7.1 <= 8.1.2

FFmpeg 6f80e2765492700622596af720534cef33dd31b4

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pavel Kohout, Aisle Research
.