CVE-2026-64830 | FFmpeg up to 8.1.2 VobSub subtitle demuxer libavformat/mpeg.c ff_subtitles_queue_insert q heap-based overflow

SecurityVulns

A vulnerability was found in FFmpeg up to 8.1.2. It has been declared as critical. The affected element is the function ff_subtitles_queue_insert of the file libavformat/mpeg.c of the component VobSub subtitle demuxer. Such manipulation of the argument q leads to heap-based buffer overflow.

This vulnerability is listed as CVE-2026-64830. The attack may be performed from remote. There is no available exploit.VulDB Recent EntriesRead More