CyberRota
← Ana sayfaya dön

CVE-2026-64832

HIGH · CVSS 8.8

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-07-22T18:17:05.483 · Çekilme zamanı: 2026-07-23T06:10:54.183021+00:00

CyberRota Yorumu

Bellek tüketimine neden olabilir.

CVE
CVE-2026-64832
Severity
HIGH
CVSS
8.8
EPSS
Yok

Orijinal NVD Açıklaması

FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surfaces remain, the ff_nvdec_start_frame_sep_ref error path frees memory via nvdec_fdd_priv_free while the calling layer subsequently frees the same frame description data, resulting in a double-free of the underlying decoder context in any FFmpeg-based application using NVDEC hardware-accelerated decoding.