Home

Description

A flaw was found in FFmpeg. A remote attacker could exploit this vulnerability by providing a specially crafted MPEG-PS/VOB media file containing a malicious DVD subtitle stream. This vulnerability is caused by a signed integer overflow in the DVD subtitle parser's fragment reassembly bounds checks, leading to a heap out-of-bounds write. Successful exploitation can result in a denial of service (DoS) due to an application crash, and potentially lead to arbitrary code execution.

PUBLISHED Reserved 2026-04-15 | Published 2026-04-15 | Updated 2026-04-15 | Assigner redhat




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Problem types

Integer Overflow or Wraparound

Product status

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Default status
affected

Timeline

2026-04-15:Reported to Red Hat.
2026-04-15:Made public.

Credits

Red Hat would like to thank Quang Luong (Calif.io in collaboration with OpenAI Codex) for reporting this issue.

References

access.redhat.com/security/cve/CVE-2026-6385 vdb-entry

bugzilla.redhat.com/show_bug.cgi?id=2458764 (RHBZ#2458764) issue-tracking

cve.org (CVE-2026-6385)

nvd.nist.gov (CVE-2026-6385)

Download JSON