CVE-2026-70632Disclosure(ffmpeg / ffmpeg)

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ffmpeg

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ffmpeg

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-07: 1Technical Details · 2026-08-07: 108-07
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - FFmpeg CFHD Decoder Heap OOB Write via AVI Probe (CVE-2026-70632) FFmpeg’s native GoPro CineForm HD (CFHD) decoder hits a heap out-of-bounds write in cfhd_decode() due to a missing output-width invariant check; during stream probing, a crafted AVI drives horiz_filter_clip() to write past the output frame buffer. Heap corruption can be leveraged for RCE by overwriting a cleanup callback pointer. 👉Affected: FFmpeg >= 4.4, < 9.0

    Post summary

    The text announces a high‑severity heap out‑of‑bounds write in FFmpeg’s CFHD decoder that could allow arbitrary code execution via a crafted AVI file; no PoC, exploit, patch, or active exploitation is mentioned.

    00000117
    282 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appffmpegffmpeg---

Explore more