FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vulnerability in the S/PDIF muxer that allows attackers to access memory beyond buffer boundaries by supplying a crafted DTS stream with a coresize value larger than the actual packet length. Attackers can exploit the missing bounds check in the spdifheader_dts4 function by providing a malicious DTS-HD audio stream during S/PDIF re-muxing to trigger unauthorized memory reads beyond the packet buffer.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "0.7.1"
},
{
"last_affected": "8.1.2"
},
{
"introduced": "6f80e2765492700622596af720534cef33dd31b4"
},
{
"last_affected": "6f80e2765492700622596af720534cef33dd31b4"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"introduced": "0.7.1"
},
{
"last_affected": "8.1.2"
}
],
"source": "CPE_FIELD"
},
{
"extracted_events": [
{
"introduced": "0.7.1"
},
{
"fixed": "8.1.2"
}
],
"source": "DESCRIPTION"
}
],
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64833.json",
"cna_assigner": "VulnCheck"
}