
If your stack processes video, you're probably running vulnerable FFmpeg right now. CVE-2026-70628: signed integer overflow in DVB subtitle parser. Heap buffer overflow. Potential RCE via crafted WTV file. Here's what to check Friday.
Post summary
The post discloses that FFmpeg contains a signed integer overflow leading to a heap buffer overflow in the DVB subtitle parser, which could allow remote code execution via crafted WTV files; no PoC, exploit, or patch is mentioned.
