Bug 2506937 (CVE-2026-66039) - CVE-2026-66039 ffmpeg: FFmpeg: Arbitrary code execution via crafted CAF file
Summary: CVE-2026-66039 ffmpeg: FFmpeg: Arbitrary code execution via crafted CAF file
Keywords:
Status: NEW
Alias: CVE-2026-66039
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-24 21:01 UTC by OSIDB Bzimport
Modified: 2026-07-30 12:56 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-24 21:01:35 UTC
FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to corrupt heap memory by supplying a crafted CAF file with a malicious bytes_per_packet value. Attackers can craft a CAF file with oversized bytes_per_packet and frames_per_packet values in the desc chunk to trigger an integer overflow in mace_decode_frame() during output sample count computation, resulting in an undersized buffer allocation and heap out-of-bounds write that could enable code execution.


Note You need to log in before you can comment on or make changes to this bug.