Executive brief
FFmpeg, a widely used multimedia framework for processing video and audio, contains a security flaw in its NVIDIA hardware acceleration component. By tricking a user into opening a specially crafted video file, an attacker could cause the application to crash or potentially execute unauthorized code. This affects any software using FFmpeg with NVIDIA NVDEC hardware decoding enabled, potentially leading to system instability or data compromise.
Technical details
A double-free vulnerability exists in libavcodec/nvdec.c within FFmpeg's NVIDIA NVDEC hardware decoder implementation. The flaw is located in the ff_nvdec_start_frame_sep_ref function; when the decoder runs out of available surfaces, an error path invokes nvdec_fdd_priv_free to release memory, which is then subsequently freed again by the calling layer. An attacker can exploit this by providing a malicious video file that triggers this specific error state, leading to heap memory corruption. This can result in a denial of service (crash) or potentially arbitrary code execution. A patch has been committed to the FFmpeg master branch to remove the redundant free call.
Affected products
- FFmpeg FFmpeg 4.4 through 8.1.2
Timeline
- 2026-06-30: other: Fix committed to upstream repository
- 2026-07-04: patched: Pull request merged into master branch
- 2026-07-22: disclosed: CVE published and advisory released by VulnCheck