What is CVE-2026-64834?
A denial-of-service vulnerability exists in FFmpeg versions 0.6.3 through 8.1.2 within the RTP/ASF demuxer, where a crafted RTP/ASF stream can trigger an infinite loop. Remote attackers can exploit this flaw by sending a malicious stream, causing service disruption. Affected users should update FFmpeg to a patched version.
Azərbaycanca: FFmpeg-in 0.6.3-dən 8.1.2 versiyalarına qədər RTP/ASF demuxer modulunda sonsuz döngü zəifliyi aşkar edilib. Xüsusi hazırlanmış RTP/ASF axını göndərən uzaqdan hücumçu xidmət rəddinə səbəb ola bilər. Təsirə məruz qalan istifadəçilər FFmpeg-i ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-400; shared vendor: FFmpeg
FAQ2
Which versions of FFmpeg are affected by CVE-2026-64834?
The CVE-2026-64834 vulnerability affects FFmpeg versions from 0.6.3 through 8.1.2.
What can an attacker achieve by exploiting CVE-2026-64834?
A remote attacker can send a crafted RTP/ASF stream to trigger an infinite loop in FFmpeg, causing a denial of service (DoS).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.