What is CVE-2026-64835?
This critical vulnerability in FFmpeg's ADX audio decoder (libavcodec/adxdec.c) allows attackers to trigger out-of-bounds reads and writes via crafted ADX or AAX files with mid-stream channel layout changes. Versions 4.4 through 8.1.2 are affected, immediate update to the latest version is strongly advised.
Azərbaycanca: Bu kritik boşluq FFmpeg-in ADX audio dekoderində (“libavcodec/adxdec.c”) aşkarlanıb və təcavüzkara xüsusi hazırlanmış ADX/AAX faylı vasitəsilə yaddaşda sərhəd pozuntusu yaradaraq oxuma və yazma əməliyyatları etməyə imkan verir. Bu, xüsusilə ortadan kanal konfiqurasiyası dəyişdirilən fayllar emal edilərkən baş verir. 4.4-dən 8.1.2-yə qədər versiyalar təsirlənib, dərhal son yeniləməyə keçmək lazımdır.
Related CVEs
link basis: same weakness class CWE-119; shared vendor: FFmpeg
FAQ2
Which software component is affected by CVE-2026-64835?
CVE-2026-64835 affects the ADX audio decoder component of FFmpeg, specifically the “libavcodec/adxdec.c” file.
What is the recommended action to protect against CVE-2026-64835?
Since FFmpeg versions 4.4 through 8.1.2 are affected, it is strongly advised to immediately update to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.