DEBIAN-CVE-2026-66040

Source
https://security-tracker.debian.org/tracker/CVE-2026-66040
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-66040.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-66040
Upstream
  • CVE-2026-66040
Published
2026-07-24T20:18:21.063Z
Modified
2026-07-26T06:00:20.930937276Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remote attackers to corrupt heap memory by supplying a crafted PNG image with a malicious eXIf chunk. Attackers can craft an eXIf chunk where multiple IFD entries reference the same large value payload, causing canonical serialization to expand the output far beyond the undersized allocation estimated by addexifprofilesize(), resulting in pngwrite_chunk() writing tens of thousands of bytes past the buffer boundary, leading to deterministic heap corruption, process crash, and potentially arbitrary code execution.

References

Affected packages

Debian:11 / ffmpeg

Package

Name
ffmpeg
Purl
pkg:deb/debian/ffmpeg?arch=source&distro=bullseye

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7:4.*
7:4.3.2-0+deb11u2
7:4.3.2-1
7:4.3.2-2
7:4.3.3-0+deb11u1
7:4.3.4-0+deb11u1
7:4.3.5-0+deb11u1
7:4.3.6-0+deb11u1
7:4.3.7-0+deb11u1
7:4.3.8-0+deb11u1
7:4.3.8-0+deb11u2
7:4.3.8-0+deb11u3
7:4.3.9-0+deb11u1
7:4.3.9-0+deb11u2
7:4.4-1
7:4.4-2
7:4.4-3
7:4.4-4
7:4.4-5
7:4.4-6
7:4.4.1-1
7:4.4.1-2
7:4.4.1-2+ports
7:4.4.1-3
7:4.4.2-1
7:5.*
7:5.0-1
7:5.0-2
7:5.0-3
7:5.0.1-1
7:5.0.1-2
7:5.0.1-3
7:5.1-1
7:5.1-2
7:5.1-2.1
7:5.1-3
7:5.1.1-1
7:5.1.1-2
7:5.1.1-2+m68k
7:5.1.2-1
7:5.1.2-2
7:5.1.2-3
7:5.1.3-1
7:5.1.3-2
7:6.*
7:6.0-1
7:6.0-2
7:6.0-3
7:6.0-4
7:6.0-5
7:6.0-6
7:6.0-7
7:6.0-8
7:6.0-9
7:6.1-1
7:6.1-2
7:6.1-3
7:6.1-4
7:6.1-5
7:6.1.1-1
7:6.1.1-2
7:6.1.1-3
7:6.1.1-4
7:6.1.1-5
7:7.*
7:7.0-1
7:7.0.1-1
7:7.0.1-2
7:7.0.1-3
7:7.0.1-4
7:7.0.1-5
7:7.0.2-1
7:7.0.2-2
7:7.0.2-3
7:7.1-1
7:7.1-2
7:7.1-3
7:7.1-4
7:7.1.1-1
7:7.1.2-1
7:7.1.3-1
7:8.*
7:8.0-1
7:8.0-2
7:8.0.1-1
7:8.0.1-2
7:8.0.1-3
7:8.1-1
7:8.1-2
7:8.1-3
7:8.1.1-1
7:8.1.1-2
7:8.1.1-3
7:8.1.1-4
7:8.1.2-1
7:8.1.2-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-66040.json"

Debian:12 / ffmpeg

Package

Name
ffmpeg
Purl
pkg:deb/debian/ffmpeg?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7:5.*
7:5.1.3-1
7:5.1.3-2
7:5.1.4-0+deb12u1
7:5.1.5-0+deb12u1
7:5.1.6-0+deb12u1
7:5.1.7-0+deb12u1
7:5.1.8-0+deb12u1
7:5.1.9-0+deb12u1
7:6.*
7:6.0-1
7:6.0-2
7:6.0-3
7:6.0-4
7:6.0-5
7:6.0-6
7:6.0-7
7:6.0-8
7:6.0-9
7:6.1-1
7:6.1-2
7:6.1-3
7:6.1-4
7:6.1-5
7:6.1.1-1
7:6.1.1-2
7:6.1.1-3
7:6.1.1-4
7:6.1.1-5
7:7.*
7:7.0-1
7:7.0.1-1
7:7.0.1-2
7:7.0.1-3
7:7.0.1-4
7:7.0.1-5
7:7.0.2-1
7:7.0.2-2
7:7.0.2-3
7:7.1-1
7:7.1-2
7:7.1-3
7:7.1-4
7:7.1.1-1
7:7.1.2-1
7:7.1.3-1
7:8.*
7:8.0-1
7:8.0-2
7:8.0.1-1
7:8.0.1-2
7:8.0.1-3
7:8.1-1
7:8.1-2
7:8.1-3
7:8.1.1-1
7:8.1.1-2
7:8.1.1-3
7:8.1.1-4
7:8.1.2-1
7:8.1.2-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-66040.json"

Debian:13 / ffmpeg

Package

Name
ffmpeg
Purl
pkg:deb/debian/ffmpeg?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7:7.*
7:7.1.1-1
7:7.1.2-0+deb13u1
7:7.1.2-1
7:7.1.3-0+deb13u1
7:7.1.3-1
7:7.1.4-0+deb13u1
7:7.1.5-0+deb13u1
7:8.*
7:8.0-1
7:8.0-2
7:8.0.1-1
7:8.0.1-2
7:8.0.1-3
7:8.1-1
7:8.1-2
7:8.1-3
7:8.1.1-1
7:8.1.1-2
7:8.1.1-3
7:8.1.1-4
7:8.1.2-1
7:8.1.2-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-66040.json"

Debian:14 / ffmpeg

Package

Name
ffmpeg
Purl
pkg:deb/debian/ffmpeg?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

7:7.*
7:7.1.1-1
7:7.1.2-1
7:7.1.3-1
7:8.*
7:8.0-1
7:8.0-2
7:8.0.1-1
7:8.0.1-2
7:8.0.1-3
7:8.1-1
7:8.1-2
7:8.1-3
7:8.1.1-1
7:8.1.1-2
7:8.1.1-3
7:8.1.1-4
7:8.1.2-1
7:8.1.2-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-66040.json"