Out-of-Bounds Read in FFmpeg S/PDIF Muxer
CVE-2026-64833
7.1HIGH
What is CVE-2026-64833?
FFmpeg versions 0.7.1 through 8.1.2 are susceptible to an out-of-bounds read vulnerability found in the S/PDIF muxer. Attackers can exploit this by sending a specially crafted DTS stream with a core_size value exceeding the actual packet length. This vulnerability originates from a lack of proper bounds checking in the spdif_header_dts4 function. During the remuxing of S/PDIF streams, a malicious DTS-HD audio stream can trigger unauthorized memory read accesses that extend beyond the designated buffer, leading to potential data leaks and system compromise.
Affected Version(s)
FFmpeg 0.7.1 <= 8.1.2
FFmpeg 0.7.1 <= 8.1.2
FFmpeg 6f80e2765492700622596af720534cef33dd31b4
