CVE-2026-66041

EUVD-2026-48743
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 43.44%
Affected Products (NVD)
VendorProductVersion
ffmpegffmpeg
7.0 ≤
𝑥
≤ 8.1.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ffmpeg
bookworm
7:5.1.9-0+deb12u1
fixed
bookworm (security)
7:5.1.9-0+deb12u1
fixed
bullseye
not-affected
forky
vulnerable
sid
vulnerable
trixie
postponed
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ffmpeg
bionic
not-affected
focal
not-affected
jammy
not-affected
noble
not-affected
resolute
needed
xenial
not-affected
libav
jammy
dne
noble
dne
resolute
dne
trusty
not-affected