{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/ffmpeg-0.7.1---8.1.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-64833"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FFmpeg (0.7.1 - 8.1.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","out-of-bounds-read","ffmpeg"],"_cs_type":"advisory","_cs_vendors":["FFmpeg"],"content_html":"\u003cp\u003eFFmpeg versions 0.7.1 through 8.1.2 are affected by an out-of-bounds read vulnerability, identified as CVE-2026-64833, residing within the S/PDIF muxer component. This flaw stems from a missing bounds check in the \u003ccode\u003espdif_header_dts4\u003c/code\u003e function. An attacker can exploit this by crafting a malicious DTS-HD audio stream where the \u003ccode\u003ecore_size\u003c/code\u003e value is intentionally larger than the actual packet length. When this specially crafted stream is processed by a vulnerable FFmpeg instance during S/PDIF re-muxing, it triggers an unauthorized read operation beyond the legitimate buffer boundaries. The vulnerability can lead to information disclosure from adjacent memory regions or result in a denial of service due to an application crash. This affects applications that utilize FFmpeg for audio processing and re-muxing of DTS streams, potentially impacting a wide range of media processing and streaming services.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker crafts a malicious DTS-HD audio stream file.\u003c/li\u003e\n\u003cli\u003eThe crafted stream's header includes a \u003ccode\u003ecore_size\u003c/code\u003e value that is intentionally larger than the actual data packet length.\u003c/li\u003e\n\u003cli\u003eThe attacker delivers this malicious DTS-HD audio file to a victim system running a vulnerable FFmpeg version.\u003c/li\u003e\n\u003cli\u003eThe victim's application processes the malicious file, initiating S/PDIF re-muxing via FFmpeg.\u003c/li\u003e\n\u003cli\u003eFFmpeg's S/PDIF muxer attempts to parse the DTS stream.\u003c/li\u003e\n\u003cli\u003eWithin the \u003ccode\u003espdif_header_dts4\u003c/code\u003e function, the missing bounds check allows a read operation to proceed using the oversized \u003ccode\u003ecore_size\u003c/code\u003e value.\u003c/li\u003e\n\u003cli\u003eThis operation accesses memory beyond the allocated buffer for the DTS packet, resulting in an out-of-bounds read.\u003c/li\u003e\n\u003cli\u003eThe out-of-bounds read leads to potential information disclosure (e.g., sensitive memory contents) or denial of service (e.g., application crash) on the victim system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-64833 can lead to a low impact on confidentiality and a high impact on availability, as indicated by its CVSS 3.1 score of 7.1. An attacker could potentially read sensitive information from memory beyond the intended buffer, though the scope of information disclosure is limited. More critically, the vulnerability can cause the FFmpeg process, and by extension, the application utilizing it, to crash, leading to a denial of service. The widespread use of FFmpeg across various media applications, streaming platforms, and development environments means that a broad range of systems could be vulnerable if they process untrusted DTS audio streams.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update all installations of FFmpeg to a version beyond 8.1.2 to remediate CVE-2026-64833.\u003c/li\u003e\n\u003cli\u003eImplement strict input validation and sanitization for all incoming DTS-HD audio streams, especially those from untrusted sources, to prevent the ingestion of maliciously crafted files.\u003c/li\u003e\n\u003cli\u003eMonitor applications utilizing FFmpeg for unexpected crashes or abnormal memory usage patterns that could indicate an attempted or successful exploitation of this vulnerability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T18:18:43Z","date_published":"2026-07-22T18:18:43Z","id":"https://feed.craftedsignal.io/briefs/2026-07-ffmpeg-oob-read/","summary":"FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer, allowing attackers to exploit a missing bounds check in the `spdif_header_dts4` function by supplying a crafted DTS stream with an oversized `core_size` value during S/PDIF re-muxing, leading to unauthorized memory reads beyond the packet buffer and potential information disclosure or denial of service.","title":"FFmpeg Out-of-Bounds Read Vulnerability in S/PDIF Muxer (CVE-2026-64833)","url":"https://feed.craftedsignal.io/briefs/2026-07-ffmpeg-oob-read/"}],"language":"en","title":"CraftedSignal Threat Feed - FFmpeg (0.7.1 - 8.1.2)","version":"https://jsonfeed.org/version/1.1"}