Out-of-Bounds Heap Write Vulnerability in FFmpeg GoPro CineForm HD Decoder
CVE-2026-70632

8.5HIGH

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-70632?

FFmpeg versions ranging from 4.4 to just below 9.0 are vulnerable to an out-of-bounds heap write in the GoPro CineForm HD decoder. This security flaw allows remote attackers to exploit the cfhd_decode() function by supplying specially crafted AVI files during stream probing. The vulnerability stems from the failure to enforce output-width constraints, leading to unauthorized writes beyond allocated memory, which could be exploited for arbitrary code execution by overwriting critical pointers in active memory.

Affected Version(s)

FFmpeg 4.4 < 9.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Adrian Junge (vurlo)
.