Vulnerability Description
FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and writes by supplying a crafted ADX or AAX audio file with a mid-stream channel layout change. When AV_PKT_DATA_NEW_EXTRADATA side data is received mid-stream, the adx_decode_frame function re-parses the stream header but fails to update the internal channel state, causing subsequent decoding operations to access the prev[] state array using a stale channel count.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ffmpeg | Ffmpeg | >= 4.4, <= 8.1.2 |
Related Weaknesses (CWE)
References
- https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5cPatch
- https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659Issue TrackingPatch
- https://www.vulncheck.com/advisories/ffmpeg-out-of-bounds-memory-access-in-adx-aThird Party Advisory
FAQ
What is CVE-2026-64835?
CVE-2026-64835 is a vulnerability with a CVSS score of 8.8 (HIGH). FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory access vulnerability in the ADX audio decoder within libavcodec/adxdec.c that allows attackers to trigger both out-of-bounds reads and...
How severe is CVE-2026-64835?
CVE-2026-64835 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-64835?
Check the references section above for vendor advisories and patch information. Affected products include: Ffmpeg Ffmpeg.