What is CVE-2026-65703?
FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder. A remote attacker can exploit this by supplying a crafted AVI file with changing frame dimensions, leading to heap corruption and potential code execution. Users should upgrade FFmpeg to the latest patched version.
Azərbaycanca: FFmpeg-in 2.7-dən 8.1.2-yə qədər versiyalarında TDSC video dekoderində "out-of-bounds write" zəifliyi aşkarlanıb. Bu, uzaqdan hücum edənə xüsusi hazırlanmış AVI faylı vasitəsilə "heap corruption" yaradaraq kod icrasına səbəb ola bilər. FFmpeg-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
Which component of FFmpeg is affected by CVE-2026-65703?
The vulnerability exists in the TDSC video decoder of FFmpeg.
What does a remote attacker need to do to exploit CVE-2026-65703?
A remote attacker can exploit this vulnerability by supplying a crafted AVI file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.