Bug 2506936 (CVE-2026-66040) - CVE-2026-66040 ffmpeg: FFmpeg: Arbitrary code execution via crafted PNG image
Summary: CVE-2026-66040 ffmpeg: FFmpeg: Arbitrary code execution via crafted PNG image
Keywords:
Status: NEW
Alias: CVE-2026-66040
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2510583 2510590 2510599 2510600 2510601
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-24 21:01 UTC by OSIDB Bzimport
Modified: 2026-08-03 10:10 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-24 21:01:29 UTC
FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by add_exif_profile_size(), resulting in png_write_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.


Note You need to log in before you can comment on or make changes to this bug.