FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhddecode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horizfilter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer.
{
"cwe_ids": [
"CWE-787"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70632.json",
"unresolved_ranges": [
{
"source": "AFFECTED_FIELD",
"extracted_events": [
{
"introduced": "4.4"
},
{
"fixed": "9.0"
}
]
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"introduced": "4.4"
},
{
"fixed": "9.0"
}
]
}
],
"cna_assigner": "VulnCheck"
}[
{
"digest": {
"line_hashes": [
"195688002327067465305765588221319015242",
"309288324102816931239308632619998175099",
"208198982209572275918917816535860937592",
"231555107084919634110330250551123341431",
"168010716807985158773806969924424380093",
"204275076296265396432751791373547480918",
"230743041424433407137898346131591666852",
"121645463046297428931382762675379161144",
"64606519716965107927271010747911179138",
"73767112427060832523002513151109600034",
"219167262246002076747638059747044171272"
],
"threshold": 0.9
},
"deprecated": false,
"id": "CVE-2026-70632-bded55e5",
"signature_version": "v1",
"source": "https://git.ffmpeg.org/ffmpeg.git@d32b387f2b0a484599d4587d651891f0c63c4238",
"signature_type": "Line",
"target": {
"file": "libavformat/rawutils.c"
}
},
{
"target": {
"file": "libavformat/rawutils.c",
"function": "ff_reshuffle_raw_rgb"
},
"id": "CVE-2026-70632-bfd07778",
"deprecated": false,
"signature_version": "v1",
"digest": {
"function_hash": "95585342688571589449512382820310933372",
"length": 1096.0
},
"signature_type": "Function",
"source": "https://git.ffmpeg.org/ffmpeg.git@d32b387f2b0a484599d4587d651891f0c63c4238"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70632.json"
"2026-09-03T08:03:54Z"
[
{
"target": {
"file": "libavformat/rawutils.c",
"function": "ff_reshuffle_raw_rgb"
},
"deprecated": false,
"id": "CVE-2026-70632-2a07b12d",
"signature_version": "v1",
"source": "https://github.com/ffmpeg/ffmpeg/commit/d32b387f2b0a484599d4587d651891f0c63c4238",
"signature_type": "Function",
"digest": {
"function_hash": "95585342688571589449512382820310933372",
"length": 1096.0
}
},
{
"target": {
"file": "libavformat/rawutils.c"
},
"id": "CVE-2026-70632-5f4309c9",
"deprecated": false,
"signature_version": "v1",
"digest": {
"line_hashes": [
"195688002327067465305765588221319015242",
"309288324102816931239308632619998175099",
"208198982209572275918917816535860937592",
"231555107084919634110330250551123341431",
"168010716807985158773806969924424380093",
"204275076296265396432751791373547480918",
"230743041424433407137898346131591666852",
"121645463046297428931382762675379161144",
"64606519716965107927271010747911179138",
"73767112427060832523002513151109600034",
"219167262246002076747638059747044171272"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/ffmpeg/ffmpeg/commit/d32b387f2b0a484599d4587d651891f0c63c4238"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70632.json"
"2026-09-03T08:03:54Z"