Ubuntu Releases Security Update for FFmpeg Vulnerabilities in USN-8716-2

Published:

Ubuntu Security Update Addresses Multiple FFmpeg Vulnerabilities

Ubuntu has released a critical security update for FFmpeg, addressing several vulnerabilities that could potentially allow attackers to execute arbitrary code or cause denial of service. This update specifically targets Ubuntu 26.04 LTS and follows the earlier advisory USN-8716-1, which also dealt with vulnerabilities in FFmpeg.

The vulnerabilities identified include issues with how FFmpeg processes various media files and streams. Notably, the following vulnerabilities have been reported:

  • CVE-2026-64830: Improper handling of crafted media files in the VobSub subtitle demuxer, which could lead to denial of service or arbitrary code execution.
  • CVE-2026-64831: Flaws in the Vulkan HEVC hardware decoder when processing crafted HEVC bitstreams, potentially resulting in denial of service or arbitrary code execution.
  • CVE-2026-64832: Issues with the NVDEC hardware decoder that could allow denial of service or arbitrary code execution through crafted video files.
  • CVE-2026-64833: Vulnerabilities in the S/PDIF muxer related to crafted DTS audio streams, which could expose sensitive information or cause denial of service.
  • CVE-2026-64834: Problems with RTP/ASF streams that could lead to denial of service.
  • CVE-2026-64835: Improper handling of crafted ADX audio files, allowing for denial of service or arbitrary code execution.
  • CVE-2026-65703: Issues with the TDSC video decoder when processing crafted AVI files, which could result in denial of service or arbitrary code execution.
  • CVE-2026-65704: Vulnerabilities in the TY demuxer affecting crafted ffconcat files, potentially leading to denial of service or arbitrary code execution.
  • CVE-2026-65705: Flaws in the vf_floodfill video filter that could allow denial of service or arbitrary code execution through crafted video streams.
  • CVE-2026-65706: Issues with the vf_swaprect video filter when handling crafted NV12 video frames, which could lead to denial of service or arbitrary code execution.
  • CVE-2026-75141: Improper handling of crafted hvcC NAL arrays in the HEVC parser, potentially resulting in denial of service or arbitrary code execution.
  • CVE-2026-75142: Vulnerabilities related to crafted MPEG system headers that could allow denial of service or arbitrary code execution.
  • CVE-2026-75143: Issues with network input in the librist protocol handler, which could lead to denial of service or arbitrary code execution.
  • CVE-2026-75144: Problems with Dirac data units in the VC2 HQ RTP packetizer, potentially resulting in denial of service or arbitrary code execution.
  • CVE-2026-75146: Vulnerabilities in DASH manifests that could expose sensitive information or cause denial of service.

Organizations using Ubuntu 26.04 LTS are strongly advised to apply this security update promptly to mitigate the risks associated with these vulnerabilities. For more detailed information and to access the update, please refer to the official advisory from Ubuntu.

Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Alleged Ploutus malware creator Anibal Canelon Aguirre appears in Nebraska court

The alleged mastermind behind the Ploutus malware, Anibal Alexander Canelon Aguirre, made his first court appearance in Nebraska after being apprehended by federal authorities....

AI-enabled threat actor JadePuffer automates destructive actions in cloud environments using Azure service principals

Recent research from Check Point has revealed that the AI-enabled threat actor known as JadePuffer, tracked as Storm-3168, is leveraging compromised Azure service principals...

FBI reports surge in AI-related online scams costing Alabamians over $6 million

The FBI has reported a significant rise in online scams fueled by artificial intelligence, marking the first time the bureau has tracked AI-related complaints...

US DHS allegedly compiles protester dossiers in Palantir database, court filing reveals

Newly unsealed court documents allege that the US Department of Homeland Security (DHS) has compiled extensive dossiers on individuals observing Immigration and Customs Enforcement...