What is CVE-2026-66039?
This is a signed integer overflow vulnerability in the MACE6 audio decoder of FFmpeg up to version 8.1.2. By supplying a crafted CAF file with a malicious bytes_per_packet value, attackers can corrupt heap memory, potentially leading to remote code execution. The issue is patched in commit aafb5c6, and immediate update is recommended.
Azərbaycanca: Bu, FFmpeg-in 8.1.2 versiyasına qədər MACE6 audio dekoderində aşkarlanmış signed integer overflow zəifliyidir. Təcavüzkar xüsusi hazırlanmış CAF faylı vasitəsilə heap yaddaşını korlayaraq uzaqdan kod icrasına səbəb ola bilər. Zəiflik aafb5c6 commit-i ilə aradan qaldırılıb, dərhal yeniləmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
How can an attacker exploit CVE-2026-66039?
By supplying a crafted CAF file, attackers can corrupt heap memory, potentially leading to remote code execution.
What should be done to remediate CVE-2026-66039?
The issue is patched in commit aafb5c6, and immediate update is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.