Home / mailings [USN-8738-1] FFmpeg vulnerabilities
Posted on 09 September 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8738-1
September 08, 2026
ffmpeg vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
Summary:
Several security issues were fixed in FFmpeg.
Software Description:
- ffmpeg: Tools for transcoding, streaming and playing of multimedia files
Details:
It was discovered that FFmpeg incorrectly handled certain video frames
when using the hqdn3d filter. An attacker could possibly use this issue
to cause a denial of service or execute arbitrary code. (CVE-2026-66036)
Adrian Junge discovered that FFmpeg incorrectly handled certain
compressed video files. An attacker could possibly use this issue to
expose sensitive information. (CVE-2026-66038)
Adrian Junge discovered that FFmpeg incorrectly handled certain audio
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-66039)
Adrian Junge discovered that FFmpeg incorrectly handled certain subtitle
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-70628)
Adrian Junge discovered that FFmpeg incorrectly handled certain video
files. An attacker could possibly use this issue to cause a denial of
service or execute arbitrary code. (CVE-2026-70632)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
ffmpeg 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavcodec-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavcodec-extra 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavcodec-extra62 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavcodec62 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavdevice-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavdevice62 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavfilter-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavfilter-extra 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavfilter-extra11 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavfilter11 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavformat-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavformat-extra 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavformat-extra62 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavformat62 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavutil-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libavutil60 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libswresample-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libswresample6 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libswscale-dev 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
libswscale9 7:8.0.1-3ubuntu2+esm3
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8738-1
CVE-2026-66036, CVE-2026-66038, CVE-2026-66039, CVE-2026-70628,
CVE-2026-70632
--===============2763356407069599862==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
