From: Bhavesh R Maheshwari <[email protected]>

Analysis:
- CVE-2026-64831 affects Vulkan HEVC hardware acceleration.[1]
- The ffmpeg recipe does not enable or build Vulkan HEVC hardware acceleration 
by default.
- Hence CVE is not applicable.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-64831

Signed-off-by: Bhavesh R Maheshwari <[email protected]>
---
 meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
 1 file changed, 1 insertion(+)

diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb 
b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 8c1969369b..af05ab4af9 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -186,3 +186,4 @@ CVE_STATUS[CVE-2025-59729] = "fixed-version: this CVE are 
fixed since v8.0"
 CVE_STATUS[CVE-2025-59730] = "fixed-version: this CVE are fixed since v8.0"
 CVE_STATUS[CVE-2026-8461] = "cpe-stable-backport: this CVE are fixed since 
v8.0.3"
 CVE_STATUS[CVE-2026-40962] = "cpe-stable-backport: this CVE are fixed since 
v8.0.2"
+CVE_STATUS[CVE-2026-64831] = "not-applicable-config: Vulkan HEVC hardware 
acceleration is not enabled or built by this recipe."
-- 
2.43.0

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245571): 
https://lists.openembedded.org/g/openembedded-core/message/245571
Mute This Topic: https://lists.openembedded.org/mt/121180418/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to