Fedora Account System
Red Hat Associate
Red Hat Customer
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process. FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vulnerability in the VobSub subtitle demuxer that allows attackers to corrupt adjacent heap memory by supplying a malicious .sub/.idx subtitle file declaring more distinct stream IDs than the fixed-size array bounds in libavformat/mpeg.c. Attackers can craft a subtitle file with excessive distinct stream IDs to trigger unbounded writes beyond the vobsub->q[] array boundary via ff_subtitles_queue_insert(), potentially achieving arbitrary code execution in any application using FFmpeg's VobSub demuxer.
*** Bug 2519511 has been marked as a duplicate of this bug. ***
Fixed in: 9.0: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dcf8ce2802bf2be1b0c6b8d4996abca7b669978d 8.1.3: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4fe710047d633ddd7a126352ce0f5f505a0fe843 NOT fixed in 7.1.x.
FEDORA-2026-3e109a0c85 (ffmpeg-8.1.3-1.fc44) has been submitted as an update to Fedora 44. https://bodhi.fedoraproject.org/updates/FEDORA-2026-3e109a0c85
FEDORA-2026-3e109a0c85 has been pushed to the Fedora 44 testing repository. Soon you'll be able to install the update with the following command: `sudo dnf upgrade --enablerepo=updates-testing --refresh --advisory=FEDORA-2026-3e109a0c85` You can provide feedback for this update here: https://bodhi.fedoraproject.org/updates/FEDORA-2026-3e109a0c85 See also https://fedoraproject.org/wiki/QA:Updates_Testing for more information on how to test updates.
FEDORA-2026-3e109a0c85 (ffmpeg-8.1.3-1.fc44) has been pushed to the Fedora 44 stable repository. If problem still persists, please make note of it in this bug report.