{"id":"ECHO-191b-44fe-7772","summary":"Heap out-of-bounds write in the native PNG/APNG encoder when writing a\ncrafted eXIf chunk (add_exif_profile_size() underestimates the sanitized\nIFD size). The eXIf-writing code does not exist in this source:\nlibavcodec/pngenc.c at n7.1.5 (and on the release/7.1 branch) has no\nEXIF/IFD handling at all; it was added in the 8.x series, which is why\nthe CVE range reads \"through 8.1.2\". Upstream fix b506fafe cannot apply\nhere because the code it patches is absent.\nRefs:\n  - https://security-tracker.debian.org/tracker/CVE-2026-66040\n  - https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc\ndetails: |\n  If this spec is ever bumped to a version whose pngenc.c writes eXIf\n  chunks (8.1+), this entry MUST be re-evaluated and converted into a\n  real PATCH_TYPE_UPSTREAM_PATCH entry.\n","modified":"2026-09-27T12:15:03.064948916Z","published":"2026-07-25T20:56:58.600Z","withdrawn":"2026-09-27T11:30:04.342Z","upstream":["CVE-2026-66040"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-66040"}],"affected":[{"package":{"name":"ffmpeg","ecosystem":"Echo","purl":"pkg:deb/echo/ffmpeg"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7:7.1.5-0+deb13u1+e5"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-191b-44fe-7772.json"}}],"schema_version":"1.9.0"}