{"id":"ECHO-f2c1-328c-2bc2","summary":"Vulnerability is in libavfilter/vf_quirc.c (QR decode via libquirc).\nDebian's ffmpeg package does not enable --enable-libquirc (default\noff; not present in debian/rules CONFIG), so the quirc filter is not\nbuilt into our binary.\nRefs:\n  - https://security-tracker.debian.org/tracker/CVE-2026-66041\n  - https://github.com/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5\ndetails: |\n  Upstream fix resizes quirc buffers when input size changes. Clean\n  upstream patch applies to the source tree, but the filter is not\n  compiled in. If --enable-libquirc is ever added to debian/rules,\n  convert this to a real PATCH_TYPE_UPSTREAM_PATCH entry.\n","modified":"2026-09-27T11:45:05.425630646Z","published":"2026-07-25T20:57:01.301Z","withdrawn":"2026-09-27T11:01:28.479Z","upstream":["CVE-2026-66041"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2026-66041"}],"affected":[{"package":{"name":"ffmpeg","ecosystem":"Echo","purl":"pkg:deb/echo/ffmpeg"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"7:7.1.5-0+deb13u1+e5"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-f2c1-328c-2bc2.json"}}],"schema_version":"1.9.0"}