USN-8716-1: FFmpeg vulnerabilities

Publication date

3 September 2026

Overview

FFmpeg could be made to crash or run programs as your login if it opened a specially crafted file.


Packages

  • ffmpeg - Tools for transcoding, streaming and playing of multimedia files

Details

It was discovered that FFmpeg incorrectly handled certain crafted media
files in the VobSub subtitle demuxer. An attacker could possibly use
this issue to cause a denial of service or execute arbitrary code.
(CVE-2026-64830)

It was discovered that FFmpeg incorrectly handled certain crafted DTS
audio streams in the S/PDIF muxer. An attacker could possibly use this
issue to cause a denial of service or expose sensitive information.
(CVE-2026-64833)

It was discovered that FFmpeg incorrectly handled certain crafted RTP/ASF
streams. An attacker could possibly use this issue to cause a denial of
service. (CVE-2026-64834)

It was discovered that FFmpeg incorrectly handled certain crafted ADX
audio files. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04
LTS. (

It was discovered that FFmpeg incorrectly handled certain crafted media
files in the VobSub subtitle demuxer. An attacker could possibly use
this issue to cause a denial of service or execute arbitrary code.
(CVE-2026-64830)

It was discovered that FFmpeg incorrectly handled certain crafted DTS
audio streams in the S/PDIF muxer. An attacker could possibly use this
issue to cause a denial of service or expose sensitive information.
(CVE-2026-64833)

It was discovered that FFmpeg incorrectly handled certain crafted RTP/ASF
streams. An attacker could possibly use this issue to cause a denial of
service. (CVE-2026-64834)

It was discovered that FFmpeg incorrectly handled certain crafted ADX
audio files. This issue only affected Ubuntu 22.04 LTS and Ubuntu 24.04
LTS. (CVE-2026-64835)

It was discovered that FFmpeg incorrectly handled certain crafted AVI
files in the TDSC video decoder. An attacker could possibly use this
issue to cause a denial of service or execute arbitrary code.
(CVE-2026-65703)

It was discovered that FFmpeg incorrectly handled certain crafted
ffconcat files processed via the TY demuxer. This issue only affected
Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS.
(CVE-2026-65704)

It was discovered that FFmpeg incorrectly handled certain crafted video
streams in the vf_floodfill video filter. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04
LTS. (CVE-2026-65705)

It was discovered that FFmpeg incorrectly handled certain crafted NV12
video frames in the vf_swaprect video filter. This issue only affected
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 22.04 LTS, and Ubuntu 24.04
LTS. (CVE-2026-65706)

It was discovered that FFmpeg incorrectly handled certain crafted hvcC
NAL arrays in the HEVC parser. An attacker could possibly use this
issue to cause a denial of service or execute arbitrary code.
(CVE-2026-75141)

It was discovered that FFmpeg incorrectly handled certain crafted MPEG
system headers. An attacker could possibly use this issue to cause a
denial of service or execute arbitrary code. (CVE-2026-75142)

It was discovered that FFmpeg incorrectly handled certain crafted
network input in the librist protocol handler. This issue only
affected Ubuntu 22.04 LTS and Ubuntu 24.04 LTS. (CVE-2026-75143)

It was discovered that FFmpeg incorrectly handled certain crafted Dirac
data units in the VC2 HQ RTP packetizer. An attacker could possibly use
this issue to cause a denial of service or execute arbitrary code.
(CVE-2026-75144)

It was discovered that FFmpeg incorrectly handled certain crafted DASH
manifests. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS,
Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2026-75146)


Update instructions

In general, a standard system update will make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
24.04 LTS noble ffmpeg –  7:6.1.1-3ubuntu5+esm13  
libavcodec-extra60 –  7:6.1.1-3ubuntu5+esm13  
libavcodec60 –  7:6.1.1-3ubuntu5+esm13  
libavfilter9 –  7:6.1.1-3ubuntu5+esm13  
libavformat-extra60 –  7:6.1.1-3ubuntu5+esm13  
libavformat60 –  7:6.1.1-3ubuntu5+esm13  
22.04 LTS jammy ffmpeg –  7:4.4.2-0ubuntu0.22.04.1+esm15  
libavcodec-extra58 –  7:4.4.2-0ubuntu0.22.04.1+esm15  
libavcodec58 –  7:4.4.2-0ubuntu0.22.04.1+esm15  
libavfilter7 –  7:4.4.2-0ubuntu0.22.04.1+esm15  
libavformat-extra58 –  7:4.4.2-0ubuntu0.22.04.1+esm15  
libavformat58 –  7:4.4.2-0ubuntu0.22.04.1+esm15  
20.04 LTS focal ffmpeg –  7:4.2.7-0ubuntu0.1+esm16  
libavcodec-extra58 –  7:4.2.7-0ubuntu0.1+esm16  
libavcodec58 –  7:4.2.7-0ubuntu0.1+esm16  
libavfilter7 –  7:4.2.7-0ubuntu0.1+esm16  
libavformat58 –  7:4.2.7-0ubuntu0.1+esm16  
18.04 LTS bionic ffmpeg –  7:3.4.11-0ubuntu0.1+esm15  
libavcodec-extra57 –  7:3.4.11-0ubuntu0.1+esm15  
libavcodec57 –  7:3.4.11-0ubuntu0.1+esm15  
libavfilter6 –  7:3.4.11-0ubuntu0.1+esm15  
libavformat57 –  7:3.4.11-0ubuntu0.1+esm15  
16.04 LTS xenial ffmpeg –  7:2.8.17-0ubuntu0.1+esm17
libavcodec-ffmpeg-extra56 –  7:2.8.17-0ubuntu0.1+esm17
libavcodec-ffmpeg56 –  7:2.8.17-0ubuntu0.1+esm17
libavfilter-ffmpeg5 –  7:2.8.17-0ubuntu0.1+esm17
libavformat-ffmpeg56 –  7:2.8.17-0ubuntu0.1+esm17

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›