Critical Vulnerabilities in ffmpeg Affecting openSUSE and SUSE Systems

Critical Vulnerabilities in ffmpeg Affecting openSUSE and SUSE Systems

First seen 8 Aug 2026, 17:35 UTC Linuxsecurity 97% similarity 72.0

Article Content

Browse articles
ThreatCluster

A series of vulnerabilities in ffmpeg-4 have been disclosed, affecting openSUSE and SUSE systems. The vulnerabilities include CVE-2026-8461, CVE-2026-12706, CVE-2026-64830, CVE-2026-64832, CVE-2026-64835, CVE-2026-66038, and CVE-2026-66039, which can lead to denial of service, arbitrary code execution, and information disclosure. The most severe, CVE-2026-64830, has a CVSS score of 8.5, indicating a high risk of exploitation. The vulnerabilities stem from issues in various decoders, including MagicYUV and VobSub. Users are advised to patch their systems immediately using the provided update instructions. The vulnerabilities were publicly disclosed between June 18 and July 24, 2026. The advisory emphasizes the importance of auditing Linux privileges to mitigate potential damage.

Key Points: • Multiple critical vulnerabilities in ffmpeg-4 affect openSUSE and SUSE systems. • CVE-2026-64830 has a CVSS score of 8.5, indicating a high risk of exploitation. • Immediate patching is recommended to prevent denial of service and arbitrary code execution.

ThreatCluster AI How this analysis works

Timeline

2026-06-18
CVE-2026-8461 published
Out-of-bounds write in the MagicYUV decoder can lead to denial of service or remote code execution.
Linuxsecurity
2026-06-19
CVE-2026-12706 published
Heap use-after-free read in the RASC video decoder can lead to denial of service.
Linuxsecurity
2026-07-22
CVE-2026-64830 published
Heap buffer overflow in the VobSub subtitle demuxer can lead to arbitrary code execution.
Linuxsecurity
2026-07-22
CVE-2026-64832 published
Double-free in the NVIDIA NVDEC hardware decoder can lead to memory corruption.
Linuxsecurity
2026-07-22
CVE-2026-64835 published
Out-of-bounds memory access in the ADX audio decoder can lead to information disclosure and memory corruption.
Linuxsecurity
2026-07-24
CVE-2026-66038 published
Exposure of uninitialized heap memory by the LCL/ZLIB video decoder can lead to sensitive information disclosure.
Linuxsecurity
2026-07-24
CVE-2026-66039 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-08
Patch released for ffmpeg vulnerabilities
SUSE and openSUSE have released updates to address the critical vulnerabilities in ffmpeg-4.
Linuxsecurity

Community

Browse all →