CVE-2026-70628

EUVD-2026-54160
FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 4.15%
Affected Products (NVD)
VendorProductVersion
ffmpegffmpeg
0.5 ≤
𝑥
< 9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ffmpeg
bookworm
vulnerable
bookworm (security)
vulnerable
forky
vulnerable
sid
7:9.0.2-1
fixed
trixie
postponed
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ffmpeg
bionic
Fixed 7:3.4.11-0ubuntu0.1+esm14
released
focal
Fixed 7:4.2.7-0ubuntu0.1+esm15
released
jammy
Fixed 7:4.4.2-0ubuntu0.22.04.1+esm14
released
noble
Fixed 7:6.1.1-3ubuntu5+esm12
released
resolute
Fixed 7:8.0.1-3ubuntu2+esm3
released
xenial
Fixed 7:2.8.17-0ubuntu0.1+esm16
released
libav
jammy
dne
noble
dne
resolute
dne
trusty
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libavcodec58_134
suse enterprise desktop 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise sap 15 SP4
4.4.8-150400.3.75.1
fixed
suse enterprise sap 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise server 15 SP4
4.4.8-150400.3.75.1
fixed
suse enterprise server 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise workstation 15 SP7
4.4.8-150600.13.55.1
fixed
libavformat58_76
suse enterprise desktop 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise sap 15 SP4
4.4.8-150400.3.75.1
fixed
suse enterprise sap 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise server 15 SP4
4.4.8-150400.3.75.1
fixed
suse enterprise server 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise workstation 15 SP7
4.4.8-150600.13.55.1
fixed
libavutil56_70
suse enterprise desktop 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise sap 15 SP4
4.4.8-150400.3.75.1
fixed
suse enterprise sap 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise server 15 SP4
4.4.8-150400.3.75.1
fixed
suse enterprise server 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise workstation 15 SP7
4.4.8-150600.13.55.1
fixed
libpostproc55_9
suse enterprise sap 15 SP4
4.4.8-150400.3.75.1
fixed
suse enterprise server 15 SP4
4.4.8-150400.3.75.1
fixed
libswresample3_9
suse enterprise desktop 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise sap 15 SP4
4.4.8-150400.3.75.1
fixed
suse enterprise sap 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise server 15 SP4
4.4.8-150400.3.75.1
fixed
suse enterprise server 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise workstation 15 SP7
4.4.8-150600.13.55.1
fixed
libswscale5_9
suse enterprise desktop 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise sap 15 SP4
4.4.8-150400.3.75.1
fixed
suse enterprise sap 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise server 15 SP4
4.4.8-150400.3.75.1
fixed
suse enterprise server 15 SP7
4.4.8-150600.13.55.1
fixed
suse enterprise workstation 15 SP7
4.4.8-150600.13.55.1
fixed