What is CVE-2026-65704?
CVE-2026-65704 is an out-of-bounds write vulnerability in FFmpeg up to version 8.1.2, triggered by a crafted ffconcat file processed with the `-safe 0` flag. This flaw in the TY demuxer can lead to heap corruption. Users should upgrade to the latest patched version.
Azərbaycanca: CVE-2026-65704 FFmpeg-in 8.1.2 versiyasına qədər olan versiyalarında "out-of-bounds write" zəifliyidir. Təcavüzkar xüsusi hazırlanmış ffconcat faylı ilə `-safe 0` bayrağı işlədildikdə heap korrupsiyasına səbəb ola bilər. Təsirə məruz qalmamaq üçün FFmpeg-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
Which versions of FFmpeg are affected by CVE-2026-65704?
This vulnerability affects FFmpeg versions up to 8.1.2.
How can I protect against CVE-2026-65704?
To avoid being affected, it is recommended to upgrade FFmpeg to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.