FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decoder that allows remote attackers to corrupt heap memory by supplying a crafted AVI file during stream probing. The cfhd_decode() function fails to enforce the non-Bayer logical output-width invariant in the transform-type-2 reconstruction path, causing horiz_filter_clip() to write oversized 16-bit sample rows far beyond the allocated output frame buffer, which can be escalated to arbitrary code execution via overwrite of a live cleanup callback pointer.
{
"sources": [
{
"id": "CVE-2026-70632",
"database_specific": {
"status": "Received"
},
"modified": "2026-08-07T18:17:22.307Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-70632",
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70632",
"imported": "2026-08-08T05:24:19.300Z",
"published": "2026-08-06T22:18:27.567Z"
},
{
"id": "GHSA-q24x-99v6-6hxc",
"imported": "2026-08-08T05:25:39.276Z",
"modified": "2026-08-07T18:31:42Z",
"html_url": "https://github.com/advisories/GHSA-q24x-99v6-6hxc",
"url": "https://api.github.com/advisories/GHSA-q24x-99v6-6hxc",
"published": "2026-08-07T00:31:21Z"
},
{
"id": "EUVD-2026-54166",
"imported": "2026-08-08T05:24:17.710Z",
"modified": "2026-08-07T17:20:24Z",
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-54166",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-54166",
"published": "2026-08-06T21:26:17Z"
}
],
"license": "CC-BY-4.0"
}