Heap Out-of-Bounds Write Vulnerability in FFmpeg Affects Multiple Versions
CVE-2026-66041

7.7HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-66041?

FFmpeg versions 7.0 through 8.1.2 are susceptible to a heap out-of-bounds write flaw within the vf_quirc filter, which may lead to memory corruption. This vulnerability arises when a crafted PGS or SUP subtitle file is processed, specifically when the second presentation's frame dimensions exceed those of the first presentation. This inconsistency can result in av_image_copy_plane() writing data beyond the allocated memory size into the libquirc grayscale image buffer, ultimately causing heap corruption. Exploitation of this flaw may lead to application crashes and the potential for executing arbitrary code.

Affected Version(s)

FFmpeg 7.0 <= 8.1.2

FFmpeg 7.0 <= 8.1.2

FFmpeg 4da9812e25894fb51d62a8875cfa8eb39b5e20f5

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrian Junge (vurlo)
.