What is CVE-2026-64831?
FFmpeg versions 8.0 through 8.1.2 contain a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder. Remote attackers can overwrite return addresses by supplying a crafted HEVC/H.265 bitstream. Users should update FFmpeg to the latest patched version.
Azərbaycanca: FFmpeg 8.0-8.1.2 versiyalarında Vulkan HEVC hardware decoder-da stack buffer overflow zəifliyi aşkar edilib. Uzaqdan hücumçular xüsusi hazırlanmış HEVC/H.265 bitstream vasitəsilə return address-ləri dəyişdirə bilər. FFmpeg-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: FFmpeg
FAQ2
What can an attacker achieve by exploiting CVE-2026-64831?
A remote attacker can overwrite return addresses by triggering a stack buffer overflow in the Vulkan HEVC hardware decoder via a crafted HEVC/H.265 bitstream.
Which versions of FFmpeg are affected by CVE-2026-64831?
FFmpeg versions 8.0 through 8.1.2 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.