threat_intelligence837 wordsRead on Arc Codex

Usn

USN-8716-2: FFmpeg vulnerabilities Publication date 9 September 2026 Overview FFmpeg could be made to crash or run programs as your login if it opened a specially crafted file. Releases Packages - ffmpeg - Tools for transcoding, streaming and playing of multimedia files Details USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides the corresponding fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64830) It was discovered that FFmpeg incorrectly handled certain crafted HEVC bitstreams in the Vulkan HEVC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64831) It was discovered that FFmpeg incorrectly handled certain crafted video files in the NVDEC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. ( USN-8716-1 fixed several vulnerabilities in FFmpeg. This update provides the corresponding fix for Ubuntu 26.04 LTS. Original advisory details: It was discovered that FFmpeg incorrectly handled certain crafted media files in the VobSub subtitle demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64830) It was discovered that FFmpeg incorrectly handled certain crafted HEVC bitstreams in the Vulkan HEVC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64831) It was discovered that FFmpeg incorrectly handled certain crafted video files in the NVDEC hardware decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64832) It was discovered that FFmpeg incorrectly handled certain crafted DTS audio streams in the S/PDIF muxer. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2026-64833) It was discovered that FFmpeg incorrectly handled certain crafted RTP/ASF streams. An attacker could possibly use this issue to cause a denial of service. (CVE-2026-64834) It was discovered that FFmpeg incorrectly handled certain crafted ADX audio files. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-64835) It was discovered that FFmpeg incorrectly handled certain crafted AVI files in the TDSC video decoder. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65703) It was discovered that FFmpeg incorrectly handled certain crafted ffconcat files processed via the TY demuxer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65704) It was discovered that FFmpeg incorrectly handled certain crafted video streams in the vf_floodfill video filter. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65705) It was discovered that FFmpeg incorrectly handled certain crafted NV12 video frames in the vf_swaprect video filter. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-65706) It was discovered that FFmpeg incorrectly handled certain crafted hvcC NAL arrays in the HEVC parser. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75141) It was discovered that FFmpeg incorrectly handled certain crafted MPEG system headers. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75142) It was discovered that FFmpeg incorrectly handled certain crafted network input in the librist protocol handler. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75143) It was discovered that FFmpeg incorrectly handled certain crafted Dirac data units in the VC2 HQ RTP packetizer. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2026-75144) It was discovered that FFmpeg incorrectly handled certain crafted DASH manifests. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2026-75146) Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions: | Ubuntu Release | Package Version | || |---|---|---|---| | 26.04 LTS resolute | ffmpeg – 7:8.0.1-3ubuntu2+esm4 | || | libavcodec-extra62 – 7:8.0.1-3ubuntu2+esm4 | ||| | libavcodec62 – 7:8.0.1-3ubuntu2+esm4 | ||| | libavfilter11 – 7:8.0.1-3ubuntu2+esm4 | ||| | libavformat-extra62 – 7:8.0.1-3ubuntu2+esm4 | ||| | libavformat62 – 7:8.0.1-3ubuntu2+esm4 | Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. References - CVE-2026-75146 - CVE-2026-75144 - CVE-2026-75143 - CVE-2026-75142 - CVE-2026-75141 - CVE-2026-65706 - CVE-2026-65705 - CVE-2026-65704 - CVE-2026-65703 - CVE-2026-64835 - CVE-2026-75146 - CVE-2026-75144 - CVE-2026-75143 - CVE-2026-75142 - CVE-2026-75141 - CVE-2026-65706 - CVE-2026-65705 - CVE-2026-65704 - CVE-2026-65703 - CVE-2026-64835 - CVE-2026-64834 - CVE-2026-64833 - CVE-2026-64832 - CVE-2026-64831 - CVE-2026-64830

How it works

Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content β€” general knowledge won't be enough. Score 70+ to count toward your certificate.

Questions are cached β€” you'll always get the same 5 for this article.