Ubuntu Releases Security Update for FFmpeg Vulnerabilities in USN-8716-2

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Ubuntu Security Update Addresses Multiple FFmpeg Vulnerabilities

Ubuntu has released a critical security update for FFmpeg, addressing several vulnerabilities that could potentially allow attackers to execute arbitrary code or cause denial of service. This update specifically targets Ubuntu 26.04 LTS and follows the earlier advisory USN-8716-1, which also dealt with vulnerabilities in FFmpeg.

The vulnerabilities identified include issues with how FFmpeg processes various media files and streams. Notably, the following vulnerabilities have been reported:

  • CVE-2026-64830: Improper handling of crafted media files in the VobSub subtitle demuxer, which could lead to denial of service or arbitrary code execution.
  • CVE-2026-64831: Flaws in the Vulkan HEVC hardware decoder when processing crafted HEVC bitstreams, potentially resulting in denial of service or arbitrary code execution.
  • CVE-2026-64832: Issues with the NVDEC hardware decoder that could allow denial of service or arbitrary code execution through crafted video files.
  • CVE-2026-64833: Vulnerabilities in the S/PDIF muxer related to crafted DTS audio streams, which could expose sensitive information or cause denial of service.
  • CVE-2026-64834: Problems with RTP/ASF streams that could lead to denial of service.
  • CVE-2026-64835: Improper handling of crafted ADX audio files, allowing for denial of service or arbitrary code execution.
  • CVE-2026-65703: Issues with the TDSC video decoder when processing crafted AVI files, which could result in denial of service or arbitrary code execution.
  • CVE-2026-65704: Vulnerabilities in the TY demuxer affecting crafted ffconcat files, potentially leading to denial of service or arbitrary code execution.
  • CVE-2026-65705: Flaws in the vf_floodfill video filter that could allow denial of service or arbitrary code execution through crafted video streams.
  • CVE-2026-65706: Issues with the vf_swaprect video filter when handling crafted NV12 video frames, which could lead to denial of service or arbitrary code execution.
  • CVE-2026-75141: Improper handling of crafted hvcC NAL arrays in the HEVC parser, potentially resulting in denial of service or arbitrary code execution.
  • CVE-2026-75142: Vulnerabilities related to crafted MPEG system headers that could allow denial of service or arbitrary code execution.
  • CVE-2026-75143: Issues with network input in the librist protocol handler, which could lead to denial of service or arbitrary code execution.
  • CVE-2026-75144: Problems with Dirac data units in the VC2 HQ RTP packetizer, potentially resulting in denial of service or arbitrary code execution.
  • CVE-2026-75146: Vulnerabilities in DASH manifests that could expose sensitive information or cause denial of service.

Organizations using Ubuntu 26.04 LTS are strongly advised to apply this security update promptly to mitigate the risks associated with these vulnerabilities. For more detailed information and to access the update, please refer to the official advisory from Ubuntu.

Follow Cyber Warriors Middle East for further cybersecurity resources, advisories and technical guidance.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

L3Harris awarded contract for VAMPIRE counter-drone system delivery

L3Harris Technologies has been awarded a contract to deliver its VAMPIRE (Vehicle-Agnostic Modular Palletized ISR Rocket Equipment) counter-unmanned system to the U.S. Navy for...

Four Hacking Groups Exploit BlueMoon Kit Targeting Chrome and Windows Vulnerabilities

A nearly identical exploit kit that targets critical vulnerabilities in both Chromium-based browsers and older versions of Windows is being actively used by at...

CWME_REVIEW_REQUIRED

Eruptions are a regular occurrence at Anak Krakatau, a small volcano located between the Indonesian islands of Java and Sumatra. While much of its...

Cybercriminals Exploit Infostealer Logs to Bypass MFA with Stolen AI Tokens

Cybercriminals are increasingly exploiting information stealer logs to hijack artificial intelligence (AI) user accounts, creating "stolen keys" that provide unauthorized access to tools from...