Bug 2507016 - CVE-2026-64835 qt5-qtwebengine: FFmpeg: Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files [fedora-all]
Summary: CVE-2026-64835 qt5-qtwebengine: FFmpeg: Arbitrary code execution, information...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: qt5-qtwebengine
Version: 45
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Jan Grulich
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["83ff0a39-fd7b-4286-b65f-2...
Depends On:
Blocks: CVE-2026-64835
TreeView+ depends on / blocked
 
Reported: 2026-07-25 08:56 UTC by Ganesh
Modified: 2026-08-17 15:37 UTC (History)
3 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-07-25 08:56:33 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count.

Comment 1 Aoife Moloney 2026-08-17 15:37:12 UTC
This bug appears to have been reported against 'rawhide' during the Fedora Linux 45 development cycle.
Changing version to 45.


Note You need to log in before you can comment on or make changes to this bug.