Junglewise Threat Intelligence

CVE-2026-65703: FFmpeg out-of-bounds write in TDSC video decoder

CVE-2026-65703 · Severity: high · CVSS 7.8 · Published 2026-07-23

Technologies: Ffmpeg. Vendors: Ffmpeg.

Executive brief

FFmpeg, a widely used multimedia framework for processing video and audio, contains a flaw in its TDSC video decoder. An attacker can exploit this by providing a specially crafted AVI video file that, when opened by a user, causes the application to crash or potentially allow the execution of unauthorized code. This could lead to a compromise of the user's system or a disruption of services that process automated video uploads.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the FFmpeg TDSC video decoder due to improper memory management during frame dimension changes. The function 'tdsc_parse_tdsf' fails to unreference an existing reference frame before calling 'av_frame_get_buffer', which leads to the reuse of stale stride (linesize) information. When 'tdsc_blit' or 'tdsc_yuv2rgb' subsequently write pixel data to the newly allocated but undersized buffer, they write beyond its boundaries. This local attack requires a user to open a malformed AVI file and can result in heap corruption, process crashes, or arbitrary code execution. The issue is addressed by ensuring 'av_frame_unref' is called before reallocation.

Affected products

  • FFmpeg FFmpeg 2.7 through 8.1.2

Timeline

  • 2026-07-10: patched: Fix committed to FFmpeg repository
  • 2026-07-23: disclosed: Vulnerability published in NVD and VulnCheck

References

Related threats