Home / mailingsPDF  

[USN-8738-1] FFmpeg vulnerabilities

Posted on 09 September 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8738-1
September 08, 2026

ffmpeg vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS

Summary:

Several security issues were fixed in FFmpeg.

Software Description:
- ffmpeg: Tools for transcoding, streaming and playing of multimedia files

Details:

It was discovered that FFmpeg incorrectly handled certain video frames
when using the hqdn3d filter. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. (CVE-2026-66036)

Adrian Junge discovered that FFmpeg incorrectly handled certain
compressed video files. An attacker could possibly use this issue to
expose sensitive information. (CVE-2026-66038)

Adrian Junge discovered that FFmpeg incorrectly handled certain audio
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-66039)

Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-70628)

Adrian Junge discovered that FFmpeg incorrectly handled certain video
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-70632)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
ffmpeg 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavcodec-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavcodec-extra 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavcodec-extra62 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavcodec62 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavdevice-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavdevice62 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavfilter-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavfilter-extra 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavfilter-extra11 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavfilter11 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavformat-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavformat-extra 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavformat-extra62 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavformat62 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavutil-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavutil60 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libswresample-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libswresample6 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libswscale-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libswscale9 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8738-1
CVE-2026-66036, CVE-2026-66038, CVE-2026-66039, CVE-2026-70628,
CVE-2026-70632

--===============2763356407069599862==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP