Junglewise Threat Intelligence

CVE-2026-65704: FFmpeg heap corruption in TY demuxer and Shorten decoder

CVE-2026-65704 · Severity: high · CVSS 7.8 · Published 2026-07-23

Technologies: Ffmpeg. Vendors: Ffmpeg.

Executive brief

FFmpeg, a widely used multimedia framework for processing audio and video, is vulnerable to a memory corruption flaw when handling specifically crafted media files. An attacker could exploit this by tricking a user or automated system into processing a malicious file, potentially leading to a complete system compromise or application crash. This vulnerability specifically affects systems processing TiVo-related (TY) media formats.

Technical details

An integer underflow vulnerability exists in FFmpeg's TY demuxer within the demux_audio() function. When processing Series 2 AC-3 audio packets, the function decrements the packet size without sufficient bounds checking, resulting in a negative value. This negative value is subsequently passed to shorten_decode_frame(), where it is cast to a size_t during a memcpy() operation. This causes a wrap-around to a value near SIZE_MAX, leading to massive out-of-bounds reads and writes relative to the Shorten decoder's bitstream buffer. Exploitation requires the victim to process a crafted .ffconcat file, typically with the '-safe 0' flag enabled. A fix has been committed to the master branch (commit de771bd527).

Affected products

  • FFmpeg FFmpeg through 8.1.2

Timeline

  • 2026-07-10: patched: Fix committed to FFmpeg master branch
  • 2026-07-23: advisory: CVE-2026-65704 published

References

Related threats