Hello Yoann, Thanks for the review. I agree that a downstream layer could enable Vulkan HEVC hardware acceleration. However, by default this configuration is not enabled or built by the ffmpeg recipe. Since the affected Vulkan HEVC code is not built with the default recipe configuration, the proposed fix would not be compiled or exercised in our default build. Could we instead handle this using a conditional CVE_STATUS, so that the CVE is marked as not applicable when Vulkan HEVC hardware acceleration is not enabled, while still allowing the CVE to be reported when the relevant configuration is enabled by a downstream layer?
Thanks, Bhavesh Maheshwari Engineer +91 8827543501 [email protected]<mailto:[email protected]> [cid:d82e07d2-bdd2-4ad9-b5ee-cc155ce89991]<https://www.einfochips.com/> ________________________________ From: [email protected] <[email protected]> on behalf of Yoann Congal via lists.openembedded.org <[email protected]> Sent: 15 September 2026 19:50 To: Bhavesh Rajesh Maheshwari <[email protected]>; [email protected] <[email protected]> Subject: [External] Re: [wrynose][oe-core][PATCH 02/10] ffmpeg: set CVE_STATUS for CVE-2026-64831 CAUTION: This email originated from outside of the organization. This message might not be safe, use caution in opening it. If in doubt, do not open the attachment nor links in the message. On Thu Sep 10, 2026 at 3:31 PM CEST, Bhavesh R Maheshwari via lists.openembedded.org wrote: > From: Bhavesh R Maheshwari <[email protected]> > > Analysis: > - CVE-2026-64831 affects Vulkan HEVC hardware acceleration.[1] > - The ffmpeg recipe does not enable or build Vulkan HEVC hardware > acceleration by default. > - Hence CVE is not applicable. > > Reference: > [1] > https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnvd.nist.gov%2Fvuln%2Fdetail%2FCVE-2026-64831&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C41484021a46a4dfe47bf08df13347c8e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639250788317922015%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=yrPdD%2BheY4S%2BI%2Blk9W25PQl%2B48IbR6hDqkjhzHwdD38%3D&reserved=0<https://nvd.nist.gov/vuln/detail/CVE-2026-64831> > > Signed-off-by: Bhavesh R Maheshwari <[email protected]> > --- > meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb > b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb > index 8c1969369b..af05ab4af9 100644 > --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb > +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb > @@ -186,3 +186,4 @@ CVE_STATUS[CVE-2025-59729] = "fixed-version: this CVE are > fixed since v8.0" > CVE_STATUS[CVE-2025-59730] = "fixed-version: this CVE are fixed since v8.0" > CVE_STATUS[CVE-2026-8461] = "cpe-stable-backport: this CVE are fixed since > v8.0.3" > CVE_STATUS[CVE-2026-40962] = "cpe-stable-backport: this CVE are fixed since > v8.0.2" > +CVE_STATUS[CVE-2026-64831] = "not-applicable-config: Vulkan HEVC hardware > acceleration is not enabled or built by this recipe." Hello, Nothing prevent a downstream layer from activating this feature. The CVE fix[0] (per NVD) is quite simple and does apply on the ffmpeg 8.0.x branch. Can you send a backport of the fix instead? I'll keep reviewing the rest of the series. [0]: https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fpulls%2F23665%2Fcommits%2Fea8087200ce91f3f296a30541a89b19ae4af19a2&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C41484021a46a4dfe47bf08df13347c8e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639250788317952327%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Svy41Azt9Tq9hacdbW%2BYKDW6HUUQGxDJ7n%2FWQKoUaus%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665/commits/ea8087200ce91f3f296a30541a89b19ae4af19a2> Thanks! -- Yoann Congal Smile ECS
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#245946): https://lists.openembedded.org/g/openembedded-core/message/245946 Mute This Topic: https://lists.openembedded.org/mt/121180418/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
