{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/ffmpeg-2.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-65703"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FFmpeg 2.7","FFmpeg 8.1.2"],"_cs_severities":["high"],"_cs_tags":["vulnerability","media-processing","code-execution"],"_cs_type":"advisory","_cs_vendors":["FFmpeg"],"content_html":"\u003cp\u003eFFmpeg versions 2.7 through 8.1.2 are susceptible to an out-of-bounds write vulnerability (CVE-2026-65703) in its TDSC video decoder. This critical flaw allows remote attackers to trigger heap corruption and potentially achieve arbitrary code execution. The vulnerability is exploited by supplying a specially crafted Audio Video Interleave (AVI) file, which maliciously alters frame dimensions across TDSF (TrueMotion Video Codec) frames. This manipulation leads to incorrect memory handling when \u003ccode\u003etdsc_parse_tdsf()\u003c/code\u003e attempts to reuse reference frames without proper de-referencing, causing \u003ccode\u003etdsc_blit()\u003c/code\u003e and \u003ccode\u003etdsc_yuv2rgb()\u003c/code\u003e functions to write attacker-controlled pixel data beyond the allocated buffer boundaries. The impact ranges from application crashes to the possibility of full system compromise if code execution is achieved. This affects any system or application that uses vulnerable FFmpeg libraries to process media files.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker crafts a malicious AVI file that utilizes the TDSF (TrueMotion Video Codec) format.\u003c/li\u003e\n\u003cli\u003eThe crafted AVI file is engineered to change frame dimensions between successive TDSF frames.\u003c/li\u003e\n\u003cli\u003eA user or automated system processes the malicious AVI file using a vulnerable FFmpeg version (2.7 through 8.1.2).\u003c/li\u003e\n\u003cli\u003eFFmpeg's \u003ccode\u003etdsc_parse_tdsf()\u003c/code\u003e function processes the malformed frame dimension changes.\u003c/li\u003e\n\u003cli\u003eDuring this processing, \u003ccode\u003etdsc_parse_tdsf()\u003c/code\u003e fails to properly unreference an existing reference frame before calling \u003ccode\u003eav_frame_get_buffer()\u003c/code\u003e for a new frame of a different size.\u003c/li\u003e\n\u003cli\u003eThis misallocation results in \u003ccode\u003etdsc_blit()\u003c/code\u003e and \u003ccode\u003etdsc_yuv2rgb()\u003c/code\u003e functions attempting to write pixel data from the new frame into an undersized, previously allocated reference frame buffer.\u003c/li\u003e\n\u003cli\u003eThe write operation extends beyond the boundaries of the allocated memory, causing an out-of-bounds write and heap corruption within the FFmpeg process.\u003c/li\u003e\n\u003cli\u003eThis heap corruption leads to an application crash and, under specific conditions, can be leveraged by the attacker to achieve arbitrary code execution on the system where FFmpeg is running.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-65703 leads to heap corruption within the FFmpeg process, primarily resulting in a denial-of-service condition due to application crashes. The vulnerability also carries the potential for arbitrary code execution, enabling remote attackers to fully compromise affected systems. While specific victim numbers or targeted sectors are not provided, any system processing untrusted media files via vulnerable FFmpeg libraries is at risk. This includes media servers, content management systems, video editing software, and potentially web applications that handle user-uploaded video content.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-65703 by upgrading FFmpeg to version 8.1.3 or later on all affected systems immediately.\u003c/li\u003e\n\u003cli\u003eImplement robust input validation and sanitization for all user-supplied media files before processing them with FFmpeg.\u003c/li\u003e\n\u003cli\u003eMonitor application logs for unexpected crashes or error messages related to media processing involving \u003ccode\u003effmpeg\u003c/code\u003e or \u003ccode\u003elibavcodec\u003c/code\u003e components.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T20:20:25Z","date_published":"2026-07-23T20:20:25Z","id":"https://feed.craftedsignal.io/briefs/2026-07-ffmpeg-out-of-bounds-write/","summary":"An out-of-bounds write vulnerability (CVE-2026-65703) exists in the TDSC video decoder within FFmpeg versions 2.7 through 8.1.2, allowing remote attackers to cause heap corruption and potential code execution by supplying a specially crafted AVI file with changing frame dimensions across TDSF frames.","title":"FFmpeg TDSC Video Decoder Out-of-Bounds Write Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-ffmpeg-out-of-bounds-write/"}],"language":"en","title":"CraftedSignal Threat Feed - FFmpeg 2.7","version":"https://jsonfeed.org/version/1.1"}