Junglewise Threat Intelligence

CVE-2026-64830: FFmpeg heap buffer overflow in VobSub subtitle demuxer

CVE-2026-64830 · Severity: high · CVSS 8.8 · Published 2026-07-22

Technologies: Ffmpeg. Vendors: Ffmpeg.

Executive brief

FFmpeg, a widely used multimedia framework for processing video and audio, is vulnerable to a memory corruption flaw when handling certain subtitle files. By tricking a user or service into processing a specially crafted VobSub (.sub/.idx) subtitle file, an attacker could crash the application or potentially execute malicious code. This affects any software that relies on FFmpeg to process subtitle data, potentially leading to full system compromise or data theft.

Technical details

A heap-based buffer overflow exists in FFmpeg's VobSub subtitle demuxer within libavformat/mpeg.c. The vulnerability is caused by a failure to properly bound the number of distinct stream IDs parsed from .sub/.idx subtitle files against the fixed-size vobsub->q[] array. An attacker can provide a crafted subtitle file that declares more stream IDs than the array can hold, leading to unbounded writes beyond the heap buffer via the ff_subtitles_queue_insert() function. This can result in heap memory corruption and arbitrary code execution. The issue has been addressed in the FFmpeg master branch by implementing stream reuse and strict bounding of the stream count.

Affected products

  • FFmpeg FFmpeg 2.1 through 8.1.2

Timeline

  • 2026-06-29: patched: Fix committed to FFmpeg master branch
  • 2026-07-02: other: Pull request merged into master branch
  • 2026-07-22: advisory: CVE-2026-64830 published

References

Related threats