{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/ffmpeg-4.4-8.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-70628"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FFmpeg (0.5 to \u003c 9.0)","FFmpeg (4.4-8.x)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","memory-corruption","ffmpeg"],"_cs_type":"advisory","_cs_vendors":["FFmpeg"],"content_html":"\u003cp\u003eFFmpeg versions ranging from 0.5 up to, but not including, 9.0 contain a critical signed integer overflow vulnerability within the DVB subtitle parser located in the \u003ccode\u003elibavcodec/dvbsub_parser.c\u003c/code\u003e source file. The vulnerability is triggered when the parser processes a maliciously crafted WTV (Windows Recorded TV) container file. During parsing, the logic responsible for bounds checking is susceptible to a signed integer overflow. Specifically, the guard expression wraps to a negative value (INT_MIN), which inadvertently bypasses the critical \u003ccode\u003ePARSE_BUF_SIZE\u003c/code\u003e comparison. This bypass leads to an unchecked \u003ccode\u003ememcpy()\u003c/code\u003e operation, resulting in an out-of-bounds heap write. Successful exploitation allows for memory corruption, which can lead to application crashes (Denial of Service) or arbitrary code execution under the context of the user running the FFmpeg-based application. Defenders should prioritize patching all internal and third-party software leveraging FFmpeg libraries to version 9.0 or later.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis vulnerability impacts any software suite or media processing pipeline that utilizes the affected versions of the FFmpeg library. Potential damage includes system compromise through arbitrary code execution or persistent service disruption via heap memory corruption. Given the prevalence of FFmpeg in media transcoders, video editors, and streaming servers, the scope of exposure is significant across multiple industry sectors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all internal and vendor-supplied software packages that bundle FFmpeg versions 0.5 through 8.9 for immediate remediation.\u003c/li\u003e\n\u003cli\u003eUpdate all instances of FFmpeg to version 9.0 or later to address the vulnerability in \u003ccode\u003elibavcodec/dvbsub_parser.c\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAudit ingestion pipelines that process WTV file formats to restrict untrusted input sources until patches are applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T23:31:35Z","date_published":"2026-08-06T23:31:28Z","id":"https://feed.craftedsignal.io/briefs/2026-08-ffmpeg-integer-overflow/","summary":"FFmpeg versions 0.5 through 8.9 are vulnerable to a signed integer overflow in the DVB subtitle parser that can be triggered via a crafted WTV file to achieve remote code execution.","title":"Heap Buffer Overflow in FFmpeg DVB Subtitle Parser","url":"https://feed.craftedsignal.io/briefs/2026-08-ffmpeg-integer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - FFmpeg (4.4-8.x)","version":"https://jsonfeed.org/version/1.1"}