{"id":"CVE-2026-70628","summary":"FFmpeg 0.5 \u003c 9.0 DVB Subtitle Parser Heap Buffer Overflow via WTV File","details":"FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsub_parser.c that allows attackers to trigger a heap buffer overflow by supplying a crafted WTV file. The overflow causes the bounds-check guard expression to wrap to INT_MIN, bypassing the PARSE_BUF_SIZE comparison and invoking memcpy() with attacker-controlled data into a heap buffer, resulting in an out-of-bounds heap write and potential memory corruption or code execution.","modified":"2026-09-05T09:55:56.474215859Z","published":"2026-08-06T21:24:15.825Z","related":["openSUSE-SU-2026:11659-1","openSUSE-SU-2026:11665-1","openSUSE-SU-2026:11682-1"],"database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-190","CWE-787"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70628.json","unresolved_ranges":[{"extracted_events":[{"introduced":"0.5"},{"fixed":"9.0"}],"source":"AFFECTED_FIELD"},{"extracted_events":[{"introduced":"0.5"},{"fixed":"9.0"}],"source":"CPE_FIELD"}]},"references":[{"type":"WEB","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg"},{"type":"WEB","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70628.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-70628"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ffmpeg-dvb-subtitle-parser-heap-buffer-overflow-via-wtv-file"},{"type":"REPORT","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897"},{"type":"FIX","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/02fc47e13f903768b75f7985a2706a6223ab4506"},{"type":"FIX","url":"https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.ffmpeg.org/ffmpeg.git","events":[{"introduced":"f8429ed58cefea1669bc127cf2b1905b4893e3f2"},{"fixed":"d32b387f2b0a484599d4587d651891f0c63c4238"}],"database_specific":{"cpe":"cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.5"},{"fixed":"9"}],"source":"CPE_RANGE"}}],"database_specific":{"vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["195688002327067465305765588221319015242","309288324102816931239308632619998175099","208198982209572275918917816535860937592","231555107084919634110330250551123341431","168010716807985158773806969924424380093","204275076296265396432751791373547480918","230743041424433407137898346131591666852","121645463046297428931382762675379161144","64606519716965107927271010747911179138","73767112427060832523002513151109600034","219167262246002076747638059747044171272"],"threshold":0.9},"id":"CVE-2026-70628-bded55e5","signature_type":"Line","signature_version":"v1","source":"https://git.ffmpeg.org/ffmpeg.git@d32b387f2b0a484599d4587d651891f0c63c4238","target":{"file":"libavformat/rawutils.c"}},{"id":"CVE-2026-70628-bfd07778","signature_type":"Function","signature_version":"v1","source":"https://git.ffmpeg.org/ffmpeg.git@d32b387f2b0a484599d4587d651891f0c63c4238","target":{"file":"libavformat/rawutils.c","function":"ff_reshuffle_raw_rgb"},"deprecated":false,"digest":{"function_hash":"95585342688571589449512382820310933372","length":1096}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70628.json","vanir_signatures_modified":"2026-09-03T08:03:53Z"}},{"ranges":[{"type":"GIT","repo":"https://github.com/ffmpeg/ffmpeg","events":[{"introduced":"f8429ed58cefea1669bc127cf2b1905b4893e3f2"},{"fixed":"d32b387f2b0a484599d4587d651891f0c63c4238"}],"database_specific":{"cpe":"cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.5"},{"fixed":"9"}],"source":"CPE_RANGE"}}],"database_specific":{"vanir_signatures_modified":"2026-09-03T08:03:53Z","vanir_signatures":[{"id":"CVE-2026-70628-2a07b12d","signature_type":"Function","signature_version":"v1","source":"https://github.com/ffmpeg/ffmpeg/commit/d32b387f2b0a484599d4587d651891f0c63c4238","target":{"function":"ff_reshuffle_raw_rgb","file":"libavformat/rawutils.c"},"deprecated":false,"digest":{"length":1096,"function_hash":"95585342688571589449512382820310933372"}},{"deprecated":false,"digest":{"threshold":0.9,"line_hashes":["195688002327067465305765588221319015242","309288324102816931239308632619998175099","208198982209572275918917816535860937592","231555107084919634110330250551123341431","168010716807985158773806969924424380093","204275076296265396432751791373547480918","230743041424433407137898346131591666852","121645463046297428931382762675379161144","64606519716965107927271010747911179138","73767112427060832523002513151109600034","219167262246002076747638059747044171272"]},"id":"CVE-2026-70628-5f4309c9","signature_type":"Line","signature_version":"v1","source":"https://github.com/ffmpeg/ffmpeg/commit/d32b387f2b0a484599d4587d651891f0c63c4238","target":{"file":"libavformat/rawutils.c"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70628.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}