{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/ffmpeg-5.x/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-64832"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FFmpeg 4.4","FFmpeg 5.x","FFmpeg 6.x","FFmpeg 7.x","FFmpeg 8.0","FFmpeg 8.1.0","FFmpeg 8.1.1","FFmpeg 8.1.2"],"_cs_severities":["high"],"_cs_tags":["vulnerability","memory-corruption","ffmpeg","nvdec","cve"],"_cs_type":"advisory","_cs_vendors":["FFmpeg","NVIDIA"],"content_html":"\u003cp\u003eA significant double-free vulnerability, tracked as CVE-2026-64832, exists in FFmpeg versions 4.4 through 8.1.2, specifically within the NVIDIA NVDEC hardware decoder component (libavcodec/nvdec.c). This flaw allows an attacker to induce memory corruption by providing a specially crafted video file to an FFmpeg-based application that utilizes NVDEC hardware-accelerated decoding. The vulnerability arises when the \u003ccode\u003eff_nvdec_start_frame_sep_ref\u003c/code\u003e error path is triggered due to a lack of available decoder surfaces. In this scenario, \u003ccode\u003envdec_fdd_priv_free\u003c/code\u003e prematurely releases memory associated with the frame description data. Subsequently, the calling layer attempts to free the same memory, leading to a double-free condition of the underlying decoder context. This issue impacts any application integrating affected FFmpeg versions and leveraging NVIDIA NVDEC for video decoding, posing a risk of application crashes, denial of service, or potentially arbitrary code execution depending on memory layout and exploitation techniques.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker crafts a malicious video file designed to trigger specific error conditions within FFmpeg's NVDEC decoding process.\u003c/li\u003e\n\u003cli\u003eThe victim opens or processes the malicious video file using an FFmpeg-based application configured for NVIDIA NVDEC hardware acceleration.\u003c/li\u003e\n\u003cli\u003eDuring the decoding process, the FFmpeg application reaches a state where no decoder surfaces are available, triggering an error path.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eff_nvdec_start_frame_sep_ref\u003c/code\u003e error handling routine is invoked within \u003ccode\u003elibavcodec/nvdec.c\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eWithin this error path, the \u003ccode\u003envdec_fdd_priv_free\u003c/code\u003e function is called, releasing the memory allocated for the frame description data.\u003c/li\u003e\n\u003cli\u003eSubsequently, the higher-level FFmpeg calling layer attempts to free the \u003cem\u003esame\u003c/em\u003e memory region for the frame description data, leading to a double-free vulnerability.\u003c/li\u003e\n\u003cli\u003eThe double-free corrupts memory, potentially causing a crash of the FFmpeg-based application, leading to a denial of service.\u003c/li\u003e\n\u003cli\u003eDepending on the memory corruption primitive and system architecture, this could be escalated to arbitrary code execution, allowing the attacker to run malicious code on the victim's system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of CVE-2026-64832 can lead to severe consequences for users of affected FFmpeg applications. The primary impact is memory corruption, which typically results in application crashes and denial of service. This could disrupt critical video processing workflows or render affected media playback applications unusable. In more sophisticated exploitation scenarios, memory corruption vulnerabilities like double-frees can be chained with other techniques to achieve arbitrary code execution, allowing attackers to compromise the underlying system. This poses a risk to any system processing untrusted video content using vulnerable FFmpeg versions with NVDEC acceleration, potentially leading to data theft, system control, or further network intrusion.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate FFmpeg to a version beyond 8.1.2 immediately to remediate CVE-2026-64832.\u003c/li\u003e\n\u003cli\u003eIdentify all applications in your environment that utilize FFmpeg for video processing, especially those configured for NVIDIA NVDEC hardware acceleration.\u003c/li\u003e\n\u003cli\u003eConsult the changelogs or security advisories for applications dependent on FFmpeg to ensure they have integrated the patched FFmpeg versions to address CVE-2026-64832.\u003c/li\u003e\n\u003cli\u003eAs a temporary mitigation if immediate patching is not possible, consider disabling NVIDIA NVDEC hardware acceleration in FFmpeg-based applications or restricting the processing of untrusted video files.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T18:17:58Z","date_published":"2026-07-22T18:17:58Z","id":"https://feed.craftedsignal.io/briefs/2026-07-ffmpeg-nvdec-double-free/","summary":"FFmpeg versions 4.4 through 8.1.2 are vulnerable to a double-free condition within the NVIDIA NVDEC hardware decoder component (libavcodec/nvdec.c), allowing attackers to trigger memory corruption by providing a specially crafted video file, which occurs when an error path frees memory via `nvdec_fdd_priv_free` due to no decoder surfaces remaining, and a subsequent layer attempts to free the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware acceleration.","title":"FFmpeg NVIDIA NVDEC Double-Free Vulnerability (CVE-2026-64832)","url":"https://feed.craftedsignal.io/briefs/2026-07-ffmpeg-nvdec-double-free/"}],"language":"en","title":"CraftedSignal Threat Feed - FFmpeg 5.x","version":"https://jsonfeed.org/version/1.1"}