{"id":"openSUSE-SU-2026:21877-1","summary":"Security update for ffmpeg-7","details":"This update for ffmpeg-7 fixes the following issues:\n\n- CVE-2023-6602: HLS Force TTY Demuxer (bsc#1220546).\n- CVE-2023-6604: HLS XBIN Demuxer DoS Amplification (bsc#1220549).\n- CVE-2024-35367: FFmpeg n6.1.1 has an Out-of-bounds Read via libavcodec/ppc/vp8dsp_altivec.c, static const vec_s8\n  h_subpel_filters_outer (bsc#1234029).\n- CVE-2024-36615: FFmpeg n7.0 has a race condition vulnerability in the VP9 decoder. This could lead to a data race if\n  video encoding parameters were being exported, as the side data would be attached in the decoder thread while\n  (bsc#1234017).\n- CVE-2025-22921: segmentation violation in NULL pointer dereference via the component /libavcodec/jpeg2000dec.c\n  (bsc#1237382).\n- CVE-2026-8461: FFmpeg: Remote code execution via out-of-bounds write in MagicYUV decoder (bsc#1269490).\n- CVE-2026-12706: ffmpeg: heap use-after-free read in RASC decoder decode_move() (bsc#1268595).\n- CVE-2026-58049: incorrect validation in the RASC video decoder can lead to an out-of-bounds heap write and memory\n  corruption (bsc#1269550).\n- CVE-2026-64833: Out-of-Bounds Read via S/PDIF Muxer spdifenc.c (bsc#1272755).\n- CVE-2026-64834: Infinite Loop DoS via RTP/ASF Demuxer (bsc#1272757).\n- CVE-2026-65703: Out-of-Bounds Write in TDSC Video Decoder (bsc#1272759).\n- CVE-2026-65704: Out-of-Bounds Write via TY Demuxer and Shorten Decoder (bsc#1272760).\n- CVE-2026-65705: vf_floodfill Out-of-Bounds Write via filter_frame() (bsc#1272761).\n- CVE-2026-65706: vf_swaprect Out-of-Bounds Write via NV12 Frame Processing (bsc#1272762).\n- CVE-2026-66036: Heap Out-of-Bounds Write in vf_hqdn3d Filter (bsc#1272763).\n- CVE-2026-66037: IAMF Demuxer Uncontrolled Resource Consumption via mix_presentation_obu() (bsc#1272764).\n- CVE-2026-70628: signed integer underflows during subtitle buffer checks can cause heap buffer overflows (bsc#1274268).\n- CVE-2026-70629: unvalidated decompressed frame sizes in video decoders can cause uninitialized heap memory reads\n  (bsc#1274270).\n- CVE-2026-70630: unvalidated decompression sizes in Screenpresso frame decoding can cause uninitialized heap memory\n  reads (bsc#1274282).\n- CVE-2026-70631: unvalidated decompression sizes in TIFF strip decoding can cause uninitialized heap memory reads\n  (bsc#1274287).\n- CVE-2026-70632: unenforced frame dimensions in CineForm HD decoding can cause heap-based out-of-bounds writes\n  (bsc#1274289).\n- CVE-2026-75141: heap buffer overflow in the hvcC box writer (bsc#1276407).\n- CVE-2026-75142: stack buffer overflow in the MPEG-PS muxer (bsc#1276408).\n- CVE-2026-75143: heap buffer overflow in the RIST protocol reader (bsc#1276409).\n- CVE-2026-75144: heap buffer overflow in the VC-2/Dirac RTP packetizer (bsc#1276410).\n- CVE-2026-75146: out-of-bounds read in the DASH demuxer (bsc#1276412).\n\nChanges for ffmpeg-7:\n\nUpdate to version 7.1.5:\n * Various crash, out-of-bounds access, add boundary check\n fixes. Affected: .mov parser, DASH parser, Snow encoder,\n Icecast, RTSP decoder, RV10/RV34 RealVideo, Truespeech,\n ADPCM, Matroska decoder\n * avcodec/jpeg2000dec: clear array length when freeing it\n (CVE-2025-22921, bsc#1237382)\n * avcodec/magicyuv: Fix 1 line MEDIAN slices\n (CVE-2026-8461, bsc#1269490)\n * avcodec/magicyuv: reject slice_height misaligned with chroma vshift.\n * avcodec/magicyuv: Expand the s-\u003einterlaced slice-height sanity check.\n * avcodec/rasc: fix heap use-after-free in decode_move().\n (CVE-2026-12706, bsc#1268595)\n * avformat/hls: Be more picky on extensions.\n (CVE-2023-6602, bsc#1220546, CVE-2023-6604, bsc#1220549)\n * lavc/vp9: Fix regression introduced in 0ba0585. It is possible that ff_progress_frame_await() is\n calledbut ff_progress_frame_report() isn't called when a hardware acceleration method is used, so\n a thread for vp9 decoding might get stuck.\n (CVE-2024-36615, bsc#1234017).\n * avcodec/vp9: Fix race when attaching side-data for show-existing frame. (commit: 0ba0585)\n (CVE-2024-36615, bsc#1234017)\n * lavc/vp9: Fix regression introduced in 0ba0585.\n * avcodec/ppc/vp8dsp_altivec: Fix out-of-bounds access h_subpel_filters_inner[i] and\n h_subpel_filters_outer[i / 2] belong together and the former allows the range 0..6.\n (CVE-2024-35367, bsc#1234029)\n","modified":"2026-09-25T18:23:47.213767381Z","published":"2026-09-18T07:48:05Z","related":["CVE-2023-6602","CVE-2023-6604","CVE-2024-35367","CVE-2024-36615","CVE-2025-22921","CVE-2026-12706","CVE-2026-58049","CVE-2026-64833","CVE-2026-64834","CVE-2026-65703","CVE-2026-65704","CVE-2026-65705","CVE-2026-65706","CVE-2026-66036","CVE-2026-66037","CVE-2026-70628","CVE-2026-70629","CVE-2026-70630","CVE-2026-70631","CVE-2026-70632","CVE-2026-75141","CVE-2026-75142","CVE-2026-75143","CVE-2026-75144","CVE-2026-75146","CVE-2026-8461"],"upstream":["CVE-2023-6602","CVE-2023-6604","CVE-2024-35367","CVE-2024-36615","CVE-2025-22921","CVE-2026-12706","CVE-2026-58049","CVE-2026-64833","CVE-2026-64834","CVE-2026-65703","CVE-2026-65704","CVE-2026-65705","CVE-2026-65706","CVE-2026-66036","CVE-2026-66037","CVE-2026-70628","CVE-2026-70629","CVE-2026-70630","CVE-2026-70631","CVE-2026-70632","CVE-2026-75141","CVE-2026-75142","CVE-2026-75143","CVE-2026-75144","CVE-2026-75146","CVE-2026-8461"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1220546"},{"type":"REPORT","url":"https://bugzilla.suse.com/1220549"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234017"},{"type":"REPORT","url":"https://bugzilla.suse.com/1234029"},{"type":"REPORT","url":"https://bugzilla.suse.com/1237382"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268595"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269490"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269550"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272755"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272757"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272759"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272760"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272761"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272762"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272763"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272764"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274268"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274270"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274282"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274287"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274289"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276407"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276408"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276409"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276410"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276412"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6602"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2023-6604"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-35367"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-36615"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-22921"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12706"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58049"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64833"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64834"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-65703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-65704"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-65705"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-65706"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-66036"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-66037"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70628"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70629"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70630"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70632"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75141"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75142"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75143"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75144"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75146"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-8461"}],"affected":[{"package":{"name":"ffmpeg-7","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/ffmpeg-7&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7.1.5-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"ffmpeg-7":"7.1.5-160000.1.1","libavcodec61":"7.1.5-160000.1.1","libpostproc58":"7.1.5-160000.1.1","ffmpeg-7-libavformat-devel":"7.1.5-160000.1.1","ffmpeg-7-libavfilter-devel":"7.1.5-160000.1.1","libavformat61":"7.1.5-160000.1.1","ffmpeg-7-libswresample-devel":"7.1.5-160000.1.1","ffmpeg-7-libavcodec-devel":"7.1.5-160000.1.1","ffmpeg-7-libswscale-devel":"7.1.5-160000.1.1","libavfilter10":"7.1.5-160000.1.1","ffmpeg-7-libavdevice-devel":"7.1.5-160000.1.1","libavutil59":"7.1.5-160000.1.1","libswscale8":"7.1.5-160000.1.1","ffmpeg-7-libpostproc-devel":"7.1.5-160000.1.1","libavdevice61":"7.1.5-160000.1.1","libswresample5":"7.1.5-160000.1.1","ffmpeg-7-libavutil-devel":"7.1.5-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21877-1.json"}}],"schema_version":"1.9.0"}