{"id":"ECHO-18b0-99b8-3f51","summary":"Vulnerability is in a Vulkan HEVC decoder code path that does not exist\nin this version.\nRefs:\n  - https://security-tracker.debian.org/tracker/CVE-2026-64831\ndetails: |\n  The vulnerable code (a stack-allocated VPS/SPS parameter struct built\n  per-frame in vk_hevc_end_frame(), overflowed by an unchecked\n  vps_num_hrd_parameters) was introduced by upstream commit 82864c21\n  (\"vulkan_hevc: use VK_KHR_video_maintenance2 if available\", 2026-03-14)\n  as part of a refactor that is not present in the 7.1.x branch. In this\n  source, vk_hevc_end_frame() has no such stack buffer: VPS HRD\n  parameters are built once into a heap buffer in\n  alloc_hevc_header_structs()/set_vps(), whose destination arrays are\n  bounded by HEVC_MAX_LAYER_SETS (1024), and vps_num_hrd_parameters is\n  already bounded by vps_num_layer_sets (\u003c=1024) at parse time in\n  libavcodec/hevc/ps.c. The CVE's own affected-version range (\"FFmpeg\n  8.0 through 8.1.2\") is consistent with this. If this spec is ever\n  bumped to \u003e=8.0, this entry MUST be re-evaluated and likely converted\n  into a real patch.\n","modified":"2026-09-15T00:47:46.102831877Z","published":"2026-07-26T15:15:03.676Z","withdrawn":"2026-07-26T15:15:03.676Z","upstream":["CVE-2026-64831"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-64831"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2026-64831"}],"affected":[{"package":{"name":"ffmpeg","ecosystem":"Echo","purl":"pkg:deb/echo/ffmpeg"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7:7.1.5-0+deb13u1"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-18b0-99b8-3f51.json"}}],"schema_version":"1.9.0"}