Hello Yoann,
Thanks for the review.
I agree that a downstream layer could enable Vulkan HEVC hardware acceleration. 
However, by default this configuration is not enabled or built by the ffmpeg 
recipe.
Since the affected Vulkan HEVC code is not built with the default recipe 
configuration, the proposed fix would not be compiled or exercised in our 
default build.
Could we instead handle this using a conditional CVE_STATUS, so that the CVE is 
marked as not applicable when Vulkan HEVC hardware acceleration is not enabled, 
while still allowing the CVE to be reported when the relevant configuration is 
enabled by a downstream layer?

Thanks,

Bhavesh Maheshwari
Engineer
+91 8827543501
[email protected]<mailto:[email protected]>
[cid:d82e07d2-bdd2-4ad9-b5ee-cc155ce89991]<https://www.einfochips.com/>
________________________________
From: [email protected] 
<[email protected]> on behalf of Yoann Congal via 
lists.openembedded.org <[email protected]>
Sent: 15 September 2026 19:50
To: Bhavesh Rajesh Maheshwari <[email protected]>; 
[email protected] 
<[email protected]>
Subject: [External] Re: [wrynose][oe-core][PATCH 02/10] ffmpeg: set CVE_STATUS 
for CVE-2026-64831


CAUTION: This email originated from outside of the organization. This message 
might not be safe, use caution in opening it. If in doubt, do not open the 
attachment nor links in the message.


On Thu Sep 10, 2026 at 3:31 PM CEST, Bhavesh R Maheshwari via 
lists.openembedded.org wrote:
> From: Bhavesh R Maheshwari <[email protected]>
>
> Analysis:
> - CVE-2026-64831 affects Vulkan HEVC hardware acceleration.[1]
> - The ffmpeg recipe does not enable or build Vulkan HEVC hardware 
> acceleration by default.
> - Hence CVE is not applicable.
>
> Reference:
> [1] 
> https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnvd.nist.gov%2Fvuln%2Fdetail%2FCVE-2026-64831&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C41484021a46a4dfe47bf08df13347c8e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639250788317922015%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=yrPdD%2BheY4S%2BI%2Blk9W25PQl%2B48IbR6hDqkjhzHwdD38%3D&reserved=0<https://nvd.nist.gov/vuln/detail/CVE-2026-64831>
>
> Signed-off-by: Bhavesh R Maheshwari <[email protected]>
> ---
>  meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
>  1 file changed, 1 insertion(+)
>
> diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb 
> b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
> index 8c1969369b..af05ab4af9 100644
> --- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
> +++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
> @@ -186,3 +186,4 @@ CVE_STATUS[CVE-2025-59729] = "fixed-version: this CVE are 
> fixed since v8.0"
>  CVE_STATUS[CVE-2025-59730] = "fixed-version: this CVE are fixed since v8.0"
>  CVE_STATUS[CVE-2026-8461] = "cpe-stable-backport: this CVE are fixed since 
> v8.0.3"
>  CVE_STATUS[CVE-2026-40962] = "cpe-stable-backport: this CVE are fixed since 
> v8.0.2"
> +CVE_STATUS[CVE-2026-64831] = "not-applicable-config: Vulkan HEVC hardware 
> acceleration is not enabled or built by this recipe."

Hello,

Nothing prevent a downstream layer from activating this feature.

The CVE fix[0] (per NVD) is quite simple and does apply on the ffmpeg
8.0.x branch. Can you send a backport of the fix instead?

I'll keep reviewing the rest of the series.

[0]: 
https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fpulls%2F23665%2Fcommits%2Fea8087200ce91f3f296a30541a89b19ae4af19a2&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C41484021a46a4dfe47bf08df13347c8e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639250788317952327%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Svy41Azt9Tq9hacdbW%2BYKDW6HUUQGxDJ7n%2FWQKoUaus%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665/commits/ea8087200ce91f3f296a30541a89b19ae4af19a2>

Thanks!
--
Yoann Congal
Smile ECS

-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#245946): 
https://lists.openembedded.org/g/openembedded-core/message/245946
Mute This Topic: https://lists.openembedded.org/mt/121180418/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to