What is CVE-2026-66036?
CVE-2026-66036 is a heap out-of-bounds write vulnerability in FFmpeg's vf_hqdn3d filter up to version 8.1.2, exploited when filtergraph reinitialization is disabled with the -re flag and a crafted video with varying frame resolutions is supplied. This vulnerability, fixed in commit 5d7112c, allows attackers to corrupt heap memory; users should update to the latest version immediately.
Azərbaycanca: CVE-2026-66036 FFmpeg-in 8.1.2 versiyasına qədər olan vf_hqdn3d filterində heap out-of-bounds write zəifliyidir. -re parametri ilə filtergraph yenidən işə salınması deaktiv edildikdə, kadr ölçüsü dəyişən xüsusi hazırlanmış video faylı vasitəsilə yaddaşı korlamağa imkan verir. Bu zəiflik commit 5d7112c ilə aradan qaldırılıb, istifadəçilərə FFmpeg-i ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-787
FAQ2
Which component of FFmpeg is affected by CVE-2026-66036?
This vulnerability affects the vf_hqdn3d filter in FFmpeg.
How can I protect myself from CVE-2026-66036?
Users are advised to update FFmpeg to the latest version containing commit 5d7112c.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.