Out-of-Bounds Write Vulnerability in FFmpeg Video Filter by FFmpeg
CVE-2026-65706

8.5HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-65706?

FFmpeg versions 3.0 through 8.1.2 suffer from an out-of-bounds write vulnerability in the vf_swaprect video filter. This vulnerability allows attackers to exploit the filter_frame() function by providing a specially crafted NV12 video frame, which has odd width dimensions. This manipulation can cause an 18-byte memory copy into an insufficiently sized heap allocation, leading to heap corruption and potential crashes, thereby creating opportunities for unauthorized code execution in the affected applications.

Affected Version(s)

FFmpeg 3.0 <= 8.1.2

FFmpeg 3.0 <= 8.1.2

FFmpeg a7e38b617b32f996beaa371bbf04b39907d7a527

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrian Junge (vurlo)
.