CVE-2026-64835

HIGH CVSS 4.0: 8.7 EPSS 0.33%
Updated Jul 28, 2026
Ffmpeg
Parameter Value
CVSS 8.7 (HIGH)
Affected Versions 4.4 — 8.1.2
Type CWE-787 (Out-of-bounds Write)
Vendor Ffmpeg
Public PoC No

FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Passive
Minimal interaction

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Weakness Type (CWE)

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Ffmpeg Ffmpeg
cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
4.4 <= 8.1.2