CVE-2026-66041
Last modified
CVE-2026-66041 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution.. EPSS estimates a 0.42% chance of exploitation in the next 30 days.
Description
FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker to corrupt heap memory by supplying a crafted PGS/SUP subtitle file with mismatched frame dimensions. Attackers can provide a subtitle file whose second presentation has larger dimensions than its first, causing av_image_copy_plane() to copy data exceeding the initial allocation size into the undersized libquirc grayscale image buffer, resulting in heap corruption and process crash with potential for code execution.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | >= 7.0, <= 8.1.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-66041?
How severe is CVE-2026-66041?
How do I fix CVE-2026-66041?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-66036FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a he…8.8
- CVE-2026-66037FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an u…5.5
- CVE-2026-66038FFmpeg through 8.1.2, fixed in commit 8670835, contains an i…6.5
- CVE-2026-66039FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a si…7.8
- CVE-2026-6604A vulnerability was identified in modelscope agentscope up t…7.3
- CVE-2026-66040FFmpeg through 8.1.2, fixed in commit b506faf, contains a he…8.8
- CVE-2026-66046Expat through 2.8.3 contains a denial of service vulnerabili…7.5
- CVE-2026-66047ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2…8.1
- CVE-2026-66048Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-66049Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-6605A security flaw has been discovered in modelscope agentscope…7.3
- CVE-2026-66050NitroShare Desktop through 0.3.4 contains a path traversal v…8.7
Are you affected by CVE-2026-66041?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
