What is CVE-2026-66041?
A heap out-of-bounds write vulnerability exists in the `vf_quirc` filter of FFmpeg versions 7.0 through 8.1.2. An attacker can corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Applying the fix introduced in commit 4da9812 is required to mitigate this issue.
Azərbaycanca: FFmpeg-in 7.0-dən 8.1.2 versiyasına qədər olan `vf_quirc` filtrində heap yaddaş kənarına yazma zəifliyi aşkarlanıb. Təcavüzkar xüsusi hazırlanmış PGS/SUP altyazı faylı ilə heap yaddaşı pozmağa nail ola bilər. Problemi aradan qaldırmaq üçün commit 4da9812 ilə gələn düzəliş tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-787; shared vendor: FFmpeg
FAQ2
In which component of FFmpeg was CVE-2026-66041 discovered?
The vulnerability was discovered in the `vf_quirc` filter.
What type of file can an attacker use to exploit this vulnerability?
An attacker can use a crafted PGS/SUP subtitle file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.