Back

HIGH

FFmpeg 7.0 - 8.1.2 Heap Out-of-Bounds Write via vf_quirc Filter

Published Jul 24, 2026

Description

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution.

Affected products

Remediation

No remediation recorded yet.

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 24, 2026
Updated Jul 29, 2026
Reserved Jul 23, 2026
CISA Vulnrichment
Updated Jul 25, 2026
NVD
Status Analyzed
Modified Aug 7, 2026
Red Hat
Severity Important
Public date Jul 24, 2026
ENISA EUVD
Assigner VulnCheck
Published Jul 24, 2026
Updated Jul 29, 2026
Exploited since n/a
EUVD-2026-48743