{"id":"SUSE-SU-2026:4150-1","summary":"Security update for ffmpeg-4","details":"This update for ffmpeg-4 fixes the following issues:\n\n- CVE-2026-58049: incorrect validation in the RASC video decoder can lead to an out-of-bounds heap write and memory\n  corruption (bsc#1269550).\n- CVE-2026-64833: Out-of-Bounds Read via S/PDIF Muxer spdifenc.c (bsc#1272755).\n- CVE-2026-64834: Infinite Loop DoS via RTP/ASF Demuxer (bsc#1272757).\n- CVE-2026-65703: Out-of-Bounds Write in TDSC Video Decoder (bsc#1272759).\n- CVE-2026-65704: Out-of-Bounds Write via TY Demuxer and Shorten Decoder (bsc#1272760).\n- CVE-2026-65705: vf_floodfill Out-of-Bounds Write via filter_frame() (bsc#1272761).\n- CVE-2026-65706: vf_swaprect Out-of-Bounds Write via NV12 Frame Processing (bsc#1272762).\n- CVE-2026-66036: Heap Out-of-Bounds Write in vf_hqdn3d Filter (bsc#1272763).\n- CVE-2026-70628: signed integer underflows during subtitle buffer checks can cause heap buffer overflows (bsc#1274268).\n- CVE-2026-70629: unvalidated decompressed frame sizes in video decoders can cause uninitialized heap memory reads\n  (bsc#1274270).\n- CVE-2026-70630: unvalidated decompression sizes in Screenpresso frame decoding can cause uninitialized heap memory\n  reads (bsc#1274282).\n- CVE-2026-70631: unvalidated decompression sizes in TIFF strip decoding can cause uninitialized heap memory reads\n  (bsc#1274287).\n- CVE-2026-70632: unenforced frame dimensions in CineForm HD decoding can cause heap-based out-of-bounds writes\n  (bsc#1274289).\n- CVE-2026-75142: stack buffer overflow in the MPEG-PS muxer (bsc#1276408).\n- CVE-2026-75143: heap buffer overflow in the RIST protocol reader (bsc#1276409).\n- CVE-2026-75144: heap buffer overflow in the VC-2/Dirac RTP packetizer (bsc#1276410).\n- CVE-2026-75146: out-of-bounds read in the DASH demuxer (bsc#1276412).\n","modified":"2026-09-15T17:00:04.820440733Z","published":"2026-09-14T08:02:56Z","related":["CVE-2026-58049","CVE-2026-64833","CVE-2026-64834","CVE-2026-65703","CVE-2026-65704","CVE-2026-65705","CVE-2026-65706","CVE-2026-66036","CVE-2026-70628","CVE-2026-70629","CVE-2026-70630","CVE-2026-70631","CVE-2026-70632","CVE-2026-75142","CVE-2026-75143","CVE-2026-75144","CVE-2026-75146"],"upstream":["CVE-2026-58049","CVE-2026-64833","CVE-2026-64834","CVE-2026-65703","CVE-2026-65704","CVE-2026-65705","CVE-2026-65706","CVE-2026-66036","CVE-2026-70628","CVE-2026-70629","CVE-2026-70630","CVE-2026-70631","CVE-2026-70632","CVE-2026-75142","CVE-2026-75143","CVE-2026-75144","CVE-2026-75146"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264150-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269550"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272755"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272757"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272759"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272760"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272761"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272762"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272763"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274268"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274270"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274282"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274287"},{"type":"REPORT","url":"https://bugzilla.suse.com/1274289"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276408"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276409"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276410"},{"type":"REPORT","url":"https://bugzilla.suse.com/1276412"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58049"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64833"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64834"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-65703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-65704"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-65705"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-65706"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-66036"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70628"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70629"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70630"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70631"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-70632"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75142"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75143"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75144"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-75146"}],"affected":[{"package":{"name":"ffmpeg-4","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/ffmpeg-4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.8-150400.3.75.1"}]}],"ecosystem_specific":{"binaries":[{"libswresample3_9":"4.4.8-150400.3.75.1","libswscale5_9":"4.4.8-150400.3.75.1","libavcodec58_134":"4.4.8-150400.3.75.1","libavformat58_76":"4.4.8-150400.3.75.1","libavutil56_70":"4.4.8-150400.3.75.1","libpostproc55_9":"4.4.8-150400.3.75.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4150-1.json"}},{"package":{"name":"ffmpeg-4","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/ffmpeg-4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.8-150400.3.75.1"}]}],"ecosystem_specific":{"binaries":[{"libswresample3_9":"4.4.8-150400.3.75.1","libswscale5_9":"4.4.8-150400.3.75.1","libavcodec58_134":"4.4.8-150400.3.75.1","libavformat58_76":"4.4.8-150400.3.75.1","libavutil56_70":"4.4.8-150400.3.75.1","libpostproc55_9":"4.4.8-150400.3.75.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4150-1.json"}},{"package":{"name":"ffmpeg-4","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/ffmpeg-4&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.8-150400.3.75.1"}]}],"ecosystem_specific":{"binaries":[{"libavutil56_70":"4.4.8-150400.3.75.1","libpostproc55_9":"4.4.8-150400.3.75.1","libswresample3_9":"4.4.8-150400.3.75.1","libswscale5_9":"4.4.8-150400.3.75.1","libavcodec58_134":"4.4.8-150400.3.75.1","libavformat58_76":"4.4.8-150400.3.75.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4150-1.json"}},{"package":{"name":"ffmpeg-4","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/ffmpeg-4&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.8-150400.3.75.1"}]}],"ecosystem_specific":{"binaries":[{"libswresample3_9":"4.4.8-150400.3.75.1","libswscale5_9":"4.4.8-150400.3.75.1","libavcodec58_134":"4.4.8-150400.3.75.1","libavformat58_76":"4.4.8-150400.3.75.1","libavutil56_70":"4.4.8-150400.3.75.1","libpostproc55_9":"4.4.8-150400.3.75.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4150-1.json"}}],"schema_version":"1.9.0"}