What is CVE-2026-64830?
CVE-2026-64830 is a heap buffer overflow vulnerability in the VobSub subtitle demuxer of FFmpeg versions 2.1 through 8.1.2. An attacker can corrupt adjacent heap memory by providing a malicious .sub/.idx file with more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg. Affected users should update FFmpeg to the latest patched version.
Azərbaycanca: CVE-2026-64830 FFmpeg-in 2.1-dən 8.1.2-yə qədər versiyalarında VobSub subtitle demuxer-də aşkarlanmış heap buffer overflow zəifliyidir. Təcavüzkar xüsusi hazırlanmış .sub/.idx faylı ilə libavformat/mpeg-dəki array sərhədlərini aşaraq bitişik heap yaddaşını korlaya bilər. Təsirlənən sistemlərdə FFmpeg-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119
FAQ2
Which versions of FFmpeg are affected by CVE-2026-64830?
This vulnerability affects FFmpeg versions 2.1 through 8.1.2.
How can an attacker exploit CVE-2026-64830?
An attacker can corrupt adjacent heap memory by providing a malicious .sub/.idx file with more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.