Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-64835— FFmpeg 4.4 - 8.1.2 Out-of-Bounds Memory Access in ADX Audio Decoder

Quick assessment

Affected
FFmpeg FFmpeg
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

FFmpeg是FFmpeg组织开源的一套可录制、转换以及流化音视频的完整解决方案。 FFmpeg 4.4版本至8.1.2版本存在缓冲区错误漏洞,该漏洞源于ADX音频解码器中libavcodec/adxdec.c存在越界内存访问问题,当mid-stream通道布局变化时,adx_decode_frame函数重新解析流头部但未能更新内部通道状态,导致后续解码操作使用过时的通道计数访问prev[]状态数组,可触发越界读取和越界写入。

CVSS 8.8 · High EPSS 0.50% · P41

Affected Version Matrix 2

VendorProduct Version RangeStatus
FFmpeg FFmpeg 4.4≤ 8.1.2 affected
1836ef96846937a6cc2443698a693104f5c0b21e affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-64835

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FFmpeg 4.4 - 8.1.2 Out-of-Bounds Memory Access in ADX Audio Decoder
Source: CVE Program / CVE List V5
Vulnerability Description
FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5
Vulnerability Title
FFmpeg 缓冲区错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
FFmpeg是FFmpeg组织开源的一套可录制、转换以及流化音视频的完整解决方案。 FFmpeg 4.4版本至8.1.2版本存在缓冲区错误漏洞,该漏洞源于ADX音频解码器中libavcodec/adxdec.c存在越界内存访问问题,当mid-stream通道布局变化时,adx_decode_frame函数重新解析流头部但未能更新内部通道状态,导致后续解码操作使用过时的通道计数访问prev[]状态数组,可触发越界读取和越界写入。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
FFmpeg FFmpeg 4.4 ~ 8.1.2 -

II. Public POCs for CVE-2026-64835

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-64835

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-64835 (2)

Vendor Advisories for CVE-2026-64835 (1)

Same Patch Batch · FFmpeg · 2026-07-22 · 6 CVEs total

CVE-2026-64831 8.8 HIGH FFmpeg 8.0 - 8.1.2 Stack Buffer Overflow in Vulkan HEVC Decoder
CVE-2026-64830 8.8 HIGH FFmpeg 2.1 - 8.1.2 Heap Buffer Overflow via VobSub Subtitle Demuxer
CVE-2026-64832 8.8 HIGH FFmpeg 4.4 - 8.1.2 Double-Free in NVDEC Hardware Decoder via nvdec.c
CVE-2026-64834 7.5 HIGH FFmpeg 0.6.3 - 8.1.2 Infinite Loop DoS via RTP/ASF Demuxer
CVE-2026-64833 7.1 HIGH FFmpeg 0.7.1 - 8.1.2 Out-of-Bounds Read via S/PDIF Muxer spdifenc.c

IV. Related Vulnerabilities

V. Comments for CVE-2026-64835

No comments yet


Leave a comment