Heap Out-of-Bounds Write Vulnerability in FFmpeg's Denoise Filter
CVE-2026-66036
7.7HIGH
What is CVE-2026-66036?
FFmpeg versions up to 8.1.2 are vulnerable to a heap out-of-bounds write issue in the vf_hqdn3d filter. When filtergraph reinitialization is disabled via the -reinit_filter 0 option, attackers can exploit this flaw by supplying a specially crafted video. The vulnerability arises due to the allocation of undersized line-history buffers when processing frames of inconsistent size, leading to memory corruption. This may allow an attacker to manipulate the application behavior or execute arbitrary code.
Affected Version(s)
FFmpeg 0 <= 8.1.2
FFmpeg 0 <= 8.1.2
FFmpeg 5d7112c60e6f0f0742ce47d448e6da0718a70f4c
