Out-of-Bounds Heap Write Vulnerability in FFmpeg GoPro CineForm HD Decoder
CVE-2026-70632
8.5HIGH
What is CVE-2026-70632?
FFmpeg versions ranging from 4.4 to just below 9.0 are vulnerable to an out-of-bounds heap write in the GoPro CineForm HD decoder. This security flaw allows remote attackers to exploit the cfhd_decode() function by supplying specially crafted AVI files during stream probing. The vulnerability stems from the failure to enforce output-width constraints, leading to unauthorized writes beyond allocated memory, which could be exploited for arbitrary code execution by overwriting critical pointers in active memory.
Affected Version(s)
FFmpeg 4.4 < 9.0
