FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsubparser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INTMIN, bypassing the PARSEBUFSIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70628.json",
"cna_assigner": "VulnCheck",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "0.5"
},
{
"fixed": "9.0"
}
],
"source": "AFFECTED_FIELD"
},
{
"extracted_events": [
{
"introduced": "0.5"
},
{
"fixed": "9.0"
}
],
"source": "CPE_FIELD"
}
],
"cwe_ids": [
"CWE-190",
"CWE-787"
]
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70628.json"
[
{
"id": "CVE-2026-70628-bded55e5",
"source": "https://git.ffmpeg.org/ffmpeg.git@d32b387f2b0a484599d4587d651891f0c63c4238",
"target": {
"file": "libavformat/rawutils.c"
},
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"195688002327067465305765588221319015242",
"309288324102816931239308632619998175099",
"208198982209572275918917816535860937592",
"231555107084919634110330250551123341431",
"168010716807985158773806969924424380093",
"204275076296265396432751791373547480918",
"230743041424433407137898346131591666852",
"121645463046297428931382762675379161144",
"64606519716965107927271010747911179138",
"73767112427060832523002513151109600034",
"219167262246002076747638059747044171272"
],
"threshold": 0.9
},
"deprecated": false
},
{
"id": "CVE-2026-70628-bfd07778",
"source": "https://git.ffmpeg.org/ffmpeg.git@d32b387f2b0a484599d4587d651891f0c63c4238",
"target": {
"function": "ff_reshuffle_raw_rgb",
"file": "libavformat/rawutils.c"
},
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 1096.0,
"function_hash": "95585342688571589449512382820310933372"
},
"deprecated": false
}
]
"2026-09-03T08:03:53Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70628.json"
[
{
"id": "CVE-2026-70628-2a07b12d",
"source": "https://github.com/ffmpeg/ffmpeg/commit/d32b387f2b0a484599d4587d651891f0c63c4238",
"target": {
"function": "ff_reshuffle_raw_rgb",
"file": "libavformat/rawutils.c"
},
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 1096.0,
"function_hash": "95585342688571589449512382820310933372"
},
"deprecated": false
},
{
"id": "CVE-2026-70628-5f4309c9",
"source": "https://github.com/ffmpeg/ffmpeg/commit/d32b387f2b0a484599d4587d651891f0c63c4238",
"target": {
"file": "libavformat/rawutils.c"
},
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"line_hashes": [
"195688002327067465305765588221319015242",
"309288324102816931239308632619998175099",
"208198982209572275918917816535860937592",
"231555107084919634110330250551123341431",
"168010716807985158773806969924424380093",
"204275076296265396432751791373547480918",
"230743041424433407137898346131591666852",
"121645463046297428931382762675379161144",
"64606519716965107927271010747911179138",
"73767112427060832523002513151109600034",
"219167262246002076747638059747044171272"
],
"threshold": 0.9
},
"deprecated": false
}
]
"2026-09-03T08:03:53Z"