Critical FFmpeg Vulnerabilities Affect Ubuntu Users

Critical FFmpeg Vulnerabilities Affect Ubuntu Users

First seen 25 Jun 2026, 16:06 UTC UbuntuLinuxsecurity 94% similarity 70.5
Share:

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities were discovered in FFmpeg, affecting Ubuntu 24.04 LTS. The first vulnerability, CVE-2025-12343, allows denial of service due to improper memory handling in the TensorFlow DNN backend. The second vulnerability, CVE-2026-40962, could lead to denial of service or arbitrary code execution due to mishandling of subsample data. Both vulnerabilities were reported by Jiasheng Jiang and Quang Luong. Users of Ubuntu 24.04 LTS are particularly at risk, while Ubuntu 26.04 LTS is not affected. Patches are available through system updates. The vulnerabilities were published on February 18, 2026, and April 16, 2026, respectively.

Key Points: • Two critical vulnerabilities in FFmpeg affect Ubuntu 24.04 LTS users. • CVE-2025-12343 allows denial of service via TensorFlow DNN backend memory issues. • CVE-2026-40962 could lead to denial of service or arbitrary code execution.

ThreatCluster AI

Timeline

2026-02-18
CVE-2025-12343 published
FFmpeg vulnerability discovered allowing denial of service due to memory handling issues.
Linuxsecurity
2026-04-16
CVE-2026-40962 published
FFmpeg vulnerability reported that could lead to denial of service or arbitrary code execution.
Linuxsecurity
2026-06-24
Patches released for vulnerabilities
Ubuntu users are urged to update their systems to mitigate the identified vulnerabilities.
Ubuntu

Community

Browse all →