{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/ffmpeg-4.4-8.1.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-64835"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FFmpeg (4.4-8.1.2)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","ffmpeg","audio-codec","memory-corruption","denial-of-service","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["FFmpeg"],"content_html":"\u003cp\u003eFFmpeg versions 4.4 through 8.1.2 are affected by a high-severity out-of-bounds memory access vulnerability, identified as CVE-2026-64835. This flaw resides specifically within the ADX audio decoder, located in the \u003ccode\u003elibavcodec/adxdec.c\u003c/code\u003e file. The vulnerability allows an attacker to trigger out-of-bounds reads and writes by providing a specially crafted ADX or AAX audio file. This malicious file must include a mid-stream channel layout change delivered via \u003ccode\u003eAV_PKT_DATA_NEW_EXTRADATA\u003c/code\u003e side data. When processed, the \u003ccode\u003eadx_decode_frame\u003c/code\u003e function re-parses the stream header but critically fails to update its internal channel state. This oversight causes subsequent decoding operations to access the \u003ccode\u003eprev[]\u003c/code\u003e state array using a stale channel count, leading to memory corruption. This vulnerability can affect any system or application utilizing FFmpeg to process ADX or AAX audio files within the specified version range.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker crafts a malicious ADX or AAX audio file containing \u003ccode\u003eAV_PKT_DATA_NEW_EXTRADATA\u003c/code\u003e side data that specifies a mid-stream channel layout change.\u003c/li\u003e\n\u003cli\u003eThe crafted audio file is delivered to a victim system or application, often via download, email, or a malicious website.\u003c/li\u003e\n\u003cli\u003eThe victim system or application uses a vulnerable FFmpeg version (4.4 through 8.1.2) to process the crafted audio file.\u003c/li\u003e\n\u003cli\u003eDuring processing, the \u003ccode\u003eadx_decode_frame\u003c/code\u003e function within \u003ccode\u003elibavcodec/adxdec.c\u003c/code\u003e encounters the \u003ccode\u003eAV_PKT_DATA_NEW_EXTRADATA\u003c/code\u003e side data and re-parses the stream header.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eadx_decode_frame\u003c/code\u003e function fails to correctly update its internal channel state following the re-parsing.\u003c/li\u003e\n\u003cli\u003eSubsequent decoding operations attempt to access the \u003ccode\u003eprev[]\u003c/code\u003e state array using the outdated (stale) channel count, resulting in an out-of-bounds memory access.\u003c/li\u003e\n\u003cli\u003eThis out-of-bounds access can lead to application crashes (denial of service), information disclosure, or, in certain exploit scenarios, arbitrary code execution within the context of the FFmpeg process.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-64835 can lead to severe consequences for systems processing ADX or AAX audio files with vulnerable FFmpeg versions. The out-of-bounds memory access can directly cause the FFmpeg application to crash, resulting in a denial of service for any media processing functionality. Depending on the memory layout and the specifics of the out-of-bounds read/write, this vulnerability could also facilitate information disclosure, allowing attackers to access sensitive data, or, in more advanced scenarios, lead to arbitrary code execution. This could grant an attacker control over the compromised system, making it a critical risk for media processing platforms, content creation tools, and any software relying on FFmpeg for audio decoding.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-64835 immediately by updating all instances of FFmpeg to a version beyond 8.1.2.\u003c/li\u003e\n\u003cli\u003eImplement strict validation and sanitization for all incoming audio files, especially ADX and AAX formats, to prevent the ingestion of crafted malicious files that could trigger CVE-2026-64835.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T18:24:07Z","date_published":"2026-07-22T18:24:07Z","id":"https://feed.craftedsignal.io/briefs/2026-07-ffmpeg-adx-oob/","summary":"A high-severity out-of-bounds memory access vulnerability, tracked as CVE-2026-64835, exists in FFmpeg versions 4.4 through 8.1.2 within the ADX audio decoder, allowing attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change, potentially leading to denial of service, information disclosure, or arbitrary code execution.","title":"FFmpeg ADX Audio Decoder Out-of-Bounds Memory Access Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-ffmpeg-adx-oob/"}],"language":"en","title":"CraftedSignal Threat Feed - FFmpeg (4.4-8.1.2)","version":"https://jsonfeed.org/version/1.1"}