-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-3e109a0c85 2026-10-01 01:11:24.198707+00:00 --------------------------------------------------------------------------------
Name : ffmpeg Product : Fedora 44 Version : 8.1.3 Release : 1.fc44 URL : https://ffmpeg.org/ Summary : A complete solution to record, convert and stream audio and video Description : FFmpeg is a leading multimedia framework, able to decode, encode, transcode, mux, demux, stream, filter and play pretty much anything that humans and machines have created. It supports the most obscure ancient formats up to the cutting edge. No matter if they were designed by some standards committee, the community or a corporation. This build of ffmpeg is limited in the number of codecs supported. -------------------------------------------------------------------------------- Update Information: Latest upstream bugfix release from 8.1 branch. Changes: https://code.ffmpeg.org/FFmpeg/FFmpeg/src/branch/release/8.1/Changelog . -------------------------------------------------------------------------------- ChangeLog: * Sat Sep 26 2026 Dominik Mierzejewski <[email protected]> - 8.1.3-1 - update to 8.1.3 - drop merged patch -------------------------------------------------------------------------------- References: [ 1 ] Bug #2494554 - CVE-2026-58049 ffmpeg: FFmpeg: Memory corruption via crafted RASC video stream [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2494554 [ 2 ] Bug #2507020 - CVE-2026-64835 ffmpeg: FFmpeg: Arbitrary code execution, information disclosure, or denial of service via crafted ADX/AAX audio files [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2507020 [ 3 ] Bug #2508218 - CVE-2026-64834 ffmpeg: Denial of Service via crafted RTP/ASF stream [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2508218 [ 4 ] Bug #2508449 - CVE-2026-66038 ffmpeg: Information disclosure via malformed zlib video stream [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2508449 [ 5 ] Bug #2510587 - CVE-2026-66036 ffmpeg: FFmpeg: Arbitrary code execution via crafted video in vf_hqdn3d filter [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2510587 [ 6 ] Bug #2510588 - CVE-2026-66041 ffmpeg: FFmpeg: Arbitrary code execution via crafted PGS/SUP subtitle file [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2510588 [ 7 ] Bug #2510589 - CVE-2026-66039 ffmpeg: FFmpeg: Arbitrary code execution via crafted CAF file [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2510589 [ 8 ] Bug #2510601 - CVE-2026-66040 ffmpeg: FFmpeg: Arbitrary code execution via crafted PNG image [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2510601 [ 9 ] Bug #2511358 - CVE-2026-66037 ffmpeg: FFmpeg: Denial of Service via uncontrolled resource consumption in IAMF demuxer [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2511358 [ 10 ] Bug #2516040 - CVE-2026-70631 ffmpeg: FFmpeg: Information disclosure via uninitialized heap memory read in TIFF decoder [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2516040 [ 11 ] Bug #2516073 - CVE-2026-70630 ffmpeg: FFmpeg: Information disclosure via uninitialized heap memory read in Screenpresso decoder [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2516073 [ 12 ] Bug #2516126 - CVE-2026-70629 ffmpeg: FFmpeg: Information disclosure via uninitialized heap memory read in RSCC decoder [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2516126 [ 13 ] Bug #2519501 - CVE-2026-64830 ffmpeg: FFmpeg: Arbitrary code execution via heap buffer overflow in VobSub subtitle demuxer. [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2519501 [ 14 ] Bug #2519576 - CVE-2026-70632 ffmpeg: FFmpeg: Arbitrary Code Execution in CFHD Decoder via Crafted AVI File [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2519576 [ 15 ] Bug #2519643 - CVE-2026-70628 ffmpeg: FFmpeg: Arbitrary code execution via crafted WTV file in DVB subtitle parser [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2519643 [ 16 ] Bug #2519667 - CVE-2026-64832 ffmpeg: FFmpeg: Arbitrary code execution via crafted video file in NVDEC hardware decoder [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2519667 [ 17 ] Bug #2525514 - CVE-2026-75147 ffmpeg: FFmpeg: Information disclosure or denial of service via crafted AV1 RTP packet [fedora-44] https://bugzilla.redhat.com/show_bug.cgi?id=2525514 [ 18 ] Bug #2525517 - CVE-2026-75146 ffmpeg: FFmpeg: Information disclosure and denial of service via out-of-bounds read in DASH demuxer [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2525517 [ 19 ] Bug #2525518 - CVE-2026-75144 ffmpeg: FFmpeg: Memory corruption via crafted Dirac data unit [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2525518 [ 20 ] Bug #2525521 - CVE-2026-75142 ffmpeg: FFmpeg: Stack Buffer Overflow in MPEG-PS Muxer [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2525521 [ 21 ] Bug #2525523 - CVE-2026-75145 ffmpeg: FFmpeg: Out-of-bounds memory access due to integer narrowing conversion [fedora-44] https://bugzilla.redhat.com/show_bug.cgi?id=2525523 [ 22 ] Bug #2526159 - CVE-2026-75143 ffmpeg: FFmpeg Heap Buffer Overflow via RIST Protocol Reader [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2526159 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-3e109a0c85' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/[email protected] Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
