FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vulnerability in the Vulkan HEVC hardware decoder that allows remote attackers to overwrite return addresses and adjacent stack frames by supplying a crafted HEVC/H.265 bitstream. Attackers can embed a malicious vpsnumhrdparameters value exceeding HEVCMAXSUBLAYERS in any supported container format to overflow stack-allocated arrays in the vkhevcend_frame function, potentially achieving arbitrary code execution.
{
"cwe_ids": [
"CWE-121"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64831.json",
"cna_assigner": "VulnCheck",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "8.0"
},
{
"last_affected": "8.1.2"
},
{
"introduced": "92737390dc133daadce47dd7d2ec8ef3d9ebcbed"
},
{
"last_affected": "92737390dc133daadce47dd7d2ec8ef3d9ebcbed"
}
]
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "8.0"
},
{
"last_affected": "8.1.2"
}
]
},
{
"source": "DESCRIPTION",
"extracted_events": [
{
"introduced": "8.0"
},
{
"fixed": "8.1.2"
}
]
}
]
}