CVE-2026-65705
Received Received - Intake

Heap Corruption in FFmpeg vf_floodfill Filter

Vulnerability report for CVE-2026-65705, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-23

Last updated on: 2026-07-23

Assigner: VulnCheck

Description

FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap memory by supplying a dynamically sized video stream with filtergraph reinitialization disabled via -reinit_filter 0. When config_input() allocates the points traversal stack based on initial frame dimensions and a subsequent larger frame is processed, filter_frame() performs flood-fill neighbor pushes beyond the original allocation boundary, resulting in heap corruption and process crash with potential for code execution depending on heap layout and process hardening.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-23
Last Modified
2026-07-23
Generated
2026-07-24
AI Q&A
2026-07-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ffmpeg ffmpeg From 3.4 (inc) to 8.1.2 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.
CWE-131 The product does not correctly calculate the size to be used when allocating a buffer, which could lead to a buffer overflow.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an out-of-bounds write vulnerability in FFmpeg versions 3.4 through 8.1.2 affecting the vf_floodfill video filter. Attackers exploit it by providing a video stream with filtergraph reinitialization disabled (-reinit_filter 0). The flaw occurs when config_input() allocates a stack based on initial frame size, but a larger frame later triggers neighbor pushes beyond allocated memory, corrupting heap and potentially causing crashes or code execution.

Detection Guidance

To detect this vulnerability, check if FFmpeg versions 3.4 through 8.1.2 are installed and if the vf_floodfill filter is used with -reinit_filter 0. Monitor for crashes during video processing with dynamic frame sizes. No specific commands are provided in the context.

Impact Analysis

If exploited, this vulnerability could crash the FFmpeg process or allow arbitrary code execution depending on heap layout and system hardening. Local attackers with access to FFmpeg could trigger heap corruption, leading to denial of service or potential system compromise if combined with other vulnerabilities.

Mitigation Strategies

Upgrade FFmpeg to a version beyond 8.1.2 where the vulnerability is patched. Avoid using the vf_floodfill filter with -reinit_filter 0. If the filter is necessary, ensure input frame sizes are consistent to prevent heap corruption.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65705. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart