[wrynose][oe-core][PATCH 01/10] ffmpeg: Fix for CVE-2026-64830

Subsystems: the rest

15 messages, 2 authors, 21d ago · open the first message on its own page

[wrynose][oe-core][PATCH 01/10] ffmpeg: Fix for CVE-2026-64830

From: <hidden>
Date: 2026-09-10 13:34:04

From: Bhavesh R Maheshwari <redacted>

Pick the patch from [1], also referenced in the NVD report [2].

[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-64830

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 .../ffmpeg/ffmpeg/CVE-2026-64830.patch        | 65 +++++++++++++++++++
 .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |  1 +
 2 files changed, 66 insertions(+)
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64830.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64830.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64830.patch
new file mode 100644
index 0000000000..79ed6a45f1
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64830.patch
@@ -0,0 +1,65 @@
+From 0ae68ee7e1bc6e2bfde10c78ccc59aa9d99f4d43 Mon Sep 17 00:00:00 2001
+From: Pavel Kohout <disclosure@aisle.com>
+Date: Mon, 29 Jun 2026 23:30:41 +0200
+Subject: [PATCH 1/9] avformat/vobsub: reuse subtitle streams and bound the
+ stream count
+
+Fixes: heap buffer overflow
+Fixes: lqaO5R1BaZGO
+Fixes: dbfe61100b (avformat/vobsub: fix several issues.)
+Found-by: Pavel Kohout (Aisle Research)
+Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
+
+CVE: CVE-2026-64830
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavformat/mpeg.c | 18 ++++++++++++++++--
+ 1 file changed, 16 insertions(+), 2 deletions(-)
+
+diff --git a/libavformat/mpeg.c b/libavformat/mpeg.c
+index a7a2ef7..1ce4bf9 100644
+--- a/libavformat/mpeg.c
++++ b/libavformat/mpeg.c
+@@ -841,6 +841,20 @@ static int vobsub_read_header(AVFormatContext *s)
+             }
+ 
+             if (!st || st->id != stream_id) {
++                st = NULL;
++                for (i = 0; i < s->nb_streams; i++) {
++                    if (s->streams[i]->id == stream_id) {
++                        st = s->streams[i];
++                        break;
++                    }
++                }
++            }
++            if (!st) {
++                if (s->nb_streams >= FF_ARRAY_ELEMS(vobsub->q)) {
++                    av_log(s, AV_LOG_ERROR, "Maximum number of subtitle streams reached\n");
++                    ret = AVERROR_INVALIDDATA;
++                    goto end;
++                }
+                 st = avformat_new_stream(s, NULL);
+                 if (!st) {
+                     ret = AVERROR(ENOMEM);
+@@ -865,14 +879,14 @@ static int vobsub_read_header(AVFormatContext *s)
+             timestamp = (hh*3600LL + mm*60LL + ss) * 1000LL + ms + delay;
+             timestamp = av_rescale_q(timestamp, av_make_q(1, 1000), st->time_base);
+ 
+-            sub = ff_subtitles_queue_insert(&vobsub->q[s->nb_streams - 1], "", 0, 0);
++            sub = ff_subtitles_queue_insert(&vobsub->q[st->index], "", 0, 0);
+             if (!sub) {
+                 ret = AVERROR(ENOMEM);
+                 goto end;
+             }
+             sub->pos = pos;
+             sub->pts = timestamp;
+-            sub->stream_index = s->nb_streams - 1;
++            sub->stream_index = st->index;
+ 
+         } else if (!strncmp(line, "alt:", 4)) {
+             const char *p = line + 4;
+-- 
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 8a6eb4eb86..8c1969369b 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -26,6 +26,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
            file://0001-fftools-resources-Fix-double-build-by-disabling-.d-f.patch \
            file://0001-ffbuild-commonmak-Consolidate-pattern-rules-for-comp.patch \
            file://0002-ffbuild-common.mak-ensure-target-directories-are-cre.patch \
+           file://CVE-2026-64830.patch \
            "
 
 SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
-- 
2.43.0

[wrynose][oe-core][PATCH 02/10] ffmpeg: set CVE_STATUS for CVE-2026-64831

From: <hidden>
Date: 2026-09-10 13:34:14

From: Bhavesh R Maheshwari <redacted>

Analysis:
- CVE-2026-64831 affects Vulkan HEVC hardware acceleration.[1]
- The ffmpeg recipe does not enable or build Vulkan HEVC hardware acceleration by default.
- Hence CVE is not applicable.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-64831

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
 1 file changed, 1 insertion(+)
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 8c1969369b..af05ab4af9 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -186,3 +186,4 @@ CVE_STATUS[CVE-2025-59729] = "fixed-version: this CVE are fixed since v8.0"
 CVE_STATUS[CVE-2025-59730] = "fixed-version: this CVE are fixed since v8.0"
 CVE_STATUS[CVE-2026-8461] = "cpe-stable-backport: this CVE are fixed since v8.0.3"
 CVE_STATUS[CVE-2026-40962] = "cpe-stable-backport: this CVE are fixed since v8.0.2"
+CVE_STATUS[CVE-2026-64831] = "not-applicable-config: Vulkan HEVC hardware acceleration is not enabled or built by this recipe."
-- 
2.43.0

[wrynose][oe-core][PATCH 03/10] ffmpeg: set CVE_STATUS for CVE-2026-64832

From: <hidden>
Date: 2026-09-10 13:34:14

From: Bhavesh R Maheshwari <redacted>

Analysis:
- CVE-2026-64832 affects NVIDIA NVDEC hardware acceleration.[1]
- The ffmpeg recipe does not enable or build NVIDIA NVDEC hardware acceleration by default.
- Hence CVE is not applicable.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-64832

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
 1 file changed, 1 insertion(+)
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index af05ab4af9..68f09c2bc4 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -187,3 +187,4 @@ CVE_STATUS[CVE-2025-59730] = "fixed-version: this CVE are fixed since v8.0"
 CVE_STATUS[CVE-2026-8461] = "cpe-stable-backport: this CVE are fixed since v8.0.3"
 CVE_STATUS[CVE-2026-40962] = "cpe-stable-backport: this CVE are fixed since v8.0.2"
 CVE_STATUS[CVE-2026-64831] = "not-applicable-config: Vulkan HEVC hardware acceleration is not enabled or built by this recipe."
+CVE_STATUS[CVE-2026-64832] = "not-applicable-config: NVIDIA NVDEC hardware acceleration is not enabled or built by this recipe."
-- 
2.43.0

[wrynose][oe-core][PATCH 05/10] ffmpeg: Fix for CVE-2026-64834

From: <hidden>
Date: 2026-09-10 13:34:14

From: Bhavesh R Maheshwari <redacted>

Pick the patch from [1], also referenced in the NVD report [2].

[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-64834

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 .../ffmpeg/ffmpeg/CVE-2026-64834.patch        | 36 +++++++++++++++++++
 .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |  1 +
 2 files changed, 37 insertions(+)
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64834.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64834.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64834.patch
new file mode 100644
index 0000000000..d4a44d293c
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64834.patch
@@ -0,0 +1,36 @@
+From 9ac8fe453e443c3fc07bf85099cc93ca100d302f Mon Sep 17 00:00:00 2001
+From: Pavel Kohout <disclosure@aisle.com>
+Date: Tue, 30 Jun 2026 21:55:16 +0200
+Subject: [PATCH 3/9] avformat/rtpdec_asf: reject ASF objects smaller than
+ their header
+
+Fixes: infinite loop
+Fixes: MzWwJdpZF2Ls
+Fixes: c2f3eec445389d67afc8c699ba23915a20cae51c (Implement RTSP-MS/ASF packet parsing.)
+Found-by: Pavel Kohout (Aisle Research)
+Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
+
+CVE: CVE-2026-64834
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavformat/rtpdec_asf.c | 2 ++
+ 1 file changed, 2 insertions(+)
+
+diff --git a/libavformat/rtpdec_asf.c b/libavformat/rtpdec_asf.c
+index b3b346f..f7fa69e 100644
+--- a/libavformat/rtpdec_asf.c
++++ b/libavformat/rtpdec_asf.c
+@@ -56,6 +56,8 @@ static int rtp_asf_fix_header(uint8_t *buf, int len)
+         uint64_t chunksize = AV_RL64(p + sizeof(ff_asf_guid));
+         int skip = 6 * 8 + 3 * 4 + sizeof(ff_asf_guid) * 2;
+         if (memcmp(p, ff_asf_file_header, sizeof(ff_asf_guid))) {
++            if (chunksize < sizeof(ff_asf_guid) + 8)
++                return -1;
+             if (chunksize > end - p)
+                 return -1;
+             p += chunksize;
+-- 
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index df7e218305..b988fe2293 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -28,6 +28,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
            file://0002-ffbuild-common.mak-ensure-target-directories-are-cre.patch \
            file://CVE-2026-64830.patch \
            file://CVE-2026-64833.patch \
+           file://CVE-2026-64834.patch \
            "
 
 SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
-- 
2.43.0

[wrynose][oe-core][PATCH 04/10] ffmpeg: Fix for CVE-2026-64833

From: <hidden>
Date: 2026-09-10 13:34:14

From: Bhavesh R Maheshwari <redacted>

Pick the patch from [1], also referenced in the NVD report [2].

[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-64833

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 .../ffmpeg/ffmpeg/CVE-2026-64833.patch        | 36 +++++++++++++++++++
 .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |  1 +
 2 files changed, 37 insertions(+)
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64833.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64833.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64833.patch
new file mode 100644
index 0000000000..407ebf0ece
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64833.patch
@@ -0,0 +1,36 @@
+From 9d412e4715b17404b5e4c6d9f0d2b5c1a100aa74 Mon Sep 17 00:00:00 2001
+From: Michael Niedermayer <michael@niedermayer.cc>
+Date: Tue, 30 Jun 2026 00:11:50 +0200
+Subject: [PATCH 2/9] avformat/spdifenc: bound DTS core_size against the packet
+ size in the HD path
+
+Fixes: out of array read
+Fixes: yBSax492UIB9
+Fixes: 482d98f69b2 (spdifenc: IEC 61937 encapsulation of DTS-HD for HDMI)
+Found-by: Pavel Kohout (Aisle Research)
+Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
+
+CVE: CVE-2026-64833
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavformat/spdifenc.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/libavformat/spdifenc.c b/libavformat/spdifenc.c
+index ab3f73d..16eebda 100644
+--- a/libavformat/spdifenc.c
++++ b/libavformat/spdifenc.c
+@@ -225,7 +225,7 @@ static int spdif_header_dts4(AVFormatContext *s, AVPacket *pkt, int core_size,
+              * (dtshd_fallback == 0) */
+             ctx->dtshd_skip = 1;
+     }
+-    if (ctx->dtshd_skip && core_size) {
++    if (ctx->dtshd_skip && core_size && core_size <= pkt->size) {
+         pkt_size = core_size;
+         if (ctx->dtshd_fallback >= 0)
+             --ctx->dtshd_skip;
+-- 
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 68f09c2bc4..df7e218305 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -27,6 +27,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
            file://0001-ffbuild-commonmak-Consolidate-pattern-rules-for-comp.patch \
            file://0002-ffbuild-common.mak-ensure-target-directories-are-cre.patch \
            file://CVE-2026-64830.patch \
+           file://CVE-2026-64833.patch \
            "
 
 SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
-- 
2.43.0

[wrynose][oe-core][PATCH 06/10] ffmpeg: Fix for CVE-2026-64835

From: <hidden>
Date: 2026-09-10 13:34:24

From: Bhavesh R Maheshwari <redacted>

Pick the patch from [1], also referenced in the NVD report [2].

[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-64835

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 .../ffmpeg/ffmpeg/CVE-2026-64835.patch        | 45 +++++++++++++++++++
 .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |  1 +
 2 files changed, 46 insertions(+)
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64835.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64835.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64835.patch
new file mode 100644
index 0000000000..735bd1176f
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-64835.patch
@@ -0,0 +1,45 @@
+From 99c7dfd80d63bf009a102d3278a9f98b2fe68002 Mon Sep 17 00:00:00 2001
+From: Pavel Kohout <disclosure@aisle.com>
+Date: Mon, 29 Jun 2026 23:46:16 +0200
+Subject: [PATCH 4/9] avcodec/adx: sync decoder channel state on NEW_EXTRADATA
+
+Fixes: out of array access
+Fixes: heaNtmHvklpe
+Fixes: 92396cee602320c714713ca2d93b53684ad57000 (avformat: add CRI AAX demuxer)
+Found-by: Pavel Kohout (Aisle Research)
+Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
+
+CVE: CVE-2026-64835
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavcodec/adxdec.c | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+diff --git a/libavcodec/adxdec.c b/libavcodec/adxdec.c
+index 21be6fe..10fd81d 100644
+--- a/libavcodec/adxdec.c
++++ b/libavcodec/adxdec.c
+@@ -172,6 +172,7 @@ static int adx_decode_frame(AVCodecContext *avctx, AVFrame *frame,
+     new_extradata = av_packet_get_side_data(avpkt, AV_PKT_DATA_NEW_EXTRADATA,
+                                             &new_extradata_size);
+     if (new_extradata && new_extradata_size > 0) {
++        int old_channels = c->channels;
+         int header_size;
+         if ((ret = adx_decode_header(avctx, new_extradata,
+                                      new_extradata_size, &header_size,
+@@ -180,6 +181,10 @@ static int adx_decode_frame(AVCodecContext *avctx, AVFrame *frame,
+             return AVERROR_INVALIDDATA;
+         }
+ 
++        c->channels      = avctx->ch_layout.nb_channels;
++        c->header_parsed = 1;
++        if (old_channels != c->channels)
++            memset(c->prev, 0, sizeof(c->prev));
+         c->eof = 0;
+     }
+ 
+-- 
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index b988fe2293..8d9e975721 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -29,6 +29,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
            file://CVE-2026-64830.patch \
            file://CVE-2026-64833.patch \
            file://CVE-2026-64834.patch \
+           file://CVE-2026-64835.patch \
            "
 
 SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
-- 
2.43.0

[wrynose][oe-core][PATCH 10/10] ffmpeg: Fix for CVE-2026-65706

From: <hidden>
Date: 2026-09-10 13:34:24

From: Bhavesh R Maheshwari <redacted>

Pick the patch from [1], also referenced in the NVD report [2].

[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-65706

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 .../ffmpeg/ffmpeg/CVE-2026-65706.patch        | 52 +++++++++++++++++++
 .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |  1 +
 2 files changed, 53 insertions(+)
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch
new file mode 100644
index 0000000000..7311ed71c0
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65706.patch
@@ -0,0 +1,52 @@
+From 825f9e837f88c0c6983b5ccb70f91a32e9168f3c Mon Sep 17 00:00:00 2001
+From: Michael Niedermayer <michael@niedermayer.cc>
+Date: Sat, 11 Jul 2026 16:46:39 +0200
+Subject: [PATCH 9/9] avfilter/vf_swaprect: size the temp row buffer for the
+ widest plane
+
+Fixes: out of array access
+Fixes: 7aj_swaprect_odd17_nv12.nut / 7aj_generate_swaprect_odd17_nv12.py
+Fixes: VRAXYvKtmKa8
+Found-by: Adrian Junge (vurlo) <adjun37@gmail.com>
+
+CVE: CVE-2026-65706
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavfilter/vf_swaprect.c | 12 +++++++++++-
+ 1 file changed, 11 insertions(+), 1 deletion(-)
+
+diff --git a/libavfilter/vf_swaprect.c b/libavfilter/vf_swaprect.c
+index 5d93f51..fe007ee 100644
+--- a/libavfilter/vf_swaprect.c
++++ b/libavfilter/vf_swaprect.c
+@@ -200,6 +200,7 @@ static int config_input(AVFilterLink *inlink)
+ {
+     AVFilterContext *ctx = inlink->dst;
+     SwapRectContext *s = ctx->priv;
++    int size = 0;
+ 
+     if (!s->w  || !s->h  ||
+         !s->x1 || !s->y1 ||
+@@ -210,7 +211,16 @@ static int config_input(AVFilterLink *inlink)
+     av_image_fill_max_pixsteps(s->pixsteps, NULL, s->desc);
+     s->nb_planes = av_pix_fmt_count_planes(inlink->format);
+ 
+-    s->temp = av_malloc_array(inlink->w, s->pixsteps[0]);
++    for (int p = 0; p < s->nb_planes; p++) {
++        int shift = p == 1 || p == 2 ? s->desc->log2_chroma_w : 0;
++        int width = AV_CEIL_RSHIFT(inlink->w, shift);
++
++        if (width > INT_MAX / s->pixsteps[p])
++            return AVERROR(EINVAL);
++        size = FFMAX(size, width * s->pixsteps[p]);
++    }
++
++    s->temp = av_malloc(size);
+     if (!s->temp)
+         return AVERROR(ENOMEM);
+ 
+-- 
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 36a9ae14f2..0bd36b2c33 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -34,6 +34,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
            file://CVE-2026-65704.patch \
            file://CVE-2026-65705_p1.patch \
            file://CVE-2026-65705_p2.patch \
+           file://CVE-2026-65706.patch \
            "
 
 SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
-- 
2.43.0

[wrynose][oe-core][PATCH 07/10] ffmpeg: Fix for CVE-2026-65703

From: <hidden>
Date: 2026-09-10 13:34:24

From: Bhavesh R Maheshwari <redacted>

Pick the patch from [1], also referenced in the NVD report [2].

[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-65703

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 .../ffmpeg/ffmpeg/CVE-2026-65703.patch        | 47 +++++++++++++++++++
 .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |  1 +
 2 files changed, 48 insertions(+)
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65703.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65703.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65703.patch
new file mode 100644
index 0000000000..67c319f17e
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65703.patch
@@ -0,0 +1,47 @@
+From d15f021e27bd2eb4b7aaeb4cc4f2f49ec3435f48 Mon Sep 17 00:00:00 2001
+From: Cloud-LHY <security@clouditera.com>
+Date: Fri, 10 Jul 2026 04:07:04 +0200
+Subject: [PATCH 5/9] avcodec/tdsc: unref the reference frame before
+ reallocating on size change
+
+Fixes: out of array access
+Fixes: tdsc_poc/ffmpeg-tdsc-linesize-report/poc.avi / gen_poc.py
+Fixes: tdsc_resize_jpeg_oob.avi / tdsc-resize-stale-linesize-jpeg-oob-generate-poc.py
+Fixes: p9xG4xGf9P7H
+Fixes: HQL7a1WgTdHZ
+Found-by: Cloud-LHY / Clouditera Security, Z.ai Security, NSFOCUS
+Found-by: Adrian Junge (vurlo)
+
+CVE: CVE-2026-65703
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavcodec/tdsc.c | 8 ++++++--
+ 1 file changed, 6 insertions(+), 2 deletions(-)
+
+diff --git a/libavcodec/tdsc.c b/libavcodec/tdsc.c
+index 8baf8e9..ecd67da 100644
+--- a/libavcodec/tdsc.c
++++ b/libavcodec/tdsc.c
+@@ -482,11 +482,15 @@ static int tdsc_parse_tdsf(AVCodecContext *avctx, int number_tiles)
+             return ret;
+         init_refframe = 1;
+     }
+-    ctx->refframe->width  = ctx->width  = w;
+-    ctx->refframe->height = ctx->height = h;
++    ctx->width  = w;
++    ctx->height = h;
+ 
+     /* Allocate the reference frame if not already done or on size change */
+     if (init_refframe) {
++        av_frame_unref(ctx->refframe);
++        ctx->refframe->format = avctx->pix_fmt;
++        ctx->refframe->width  = w;
++        ctx->refframe->height = h;
+         ret = av_frame_get_buffer(ctx->refframe, 0);
+         if (ret < 0)
+             return ret;
+-- 
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 8d9e975721..7f0cdd4577 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -30,6 +30,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
            file://CVE-2026-64833.patch \
            file://CVE-2026-64834.patch \
            file://CVE-2026-64835.patch \
+           file://CVE-2026-65703.patch \
            "
 
 SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
-- 
2.43.0

[wrynose][oe-core][PATCH 08/10] ffmpeg: Fix for CVE-2026-65704

From: <hidden>
Date: 2026-09-10 13:34:25

From: Bhavesh R Maheshwari <redacted>

Pick the patch from [1], also referenced in the NVD report [2].

[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7
[2] https://nvd.nist.gov/vuln/detail/CVE-2026-65704

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 .../ffmpeg/ffmpeg/CVE-2026-65704.patch        | 35 +++++++++++++++++++
 .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |  1 +
 2 files changed, 36 insertions(+)
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65704.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65704.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65704.patch
new file mode 100644
index 0000000000..223fd03c33
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65704.patch
@@ -0,0 +1,35 @@
+From e6f2209a3ab20ef0489395697a1882e97658b5b9 Mon Sep 17 00:00:00 2001
+From: Michael Niedermayer <michael@niedermayer.cc>
+Date: Fri, 10 Jul 2026 04:07:35 +0200
+Subject: [PATCH 6/9] avformat/ty: don't let the Series2 AC3 trim underflow the
+ packet size
+
+Fixes: negative-size-param
+Fixes: ty-s2-ac3-negative-size-single-file.ffconcat / create_poc.py
+Fixes: g0qeE6KvrjZi
+Found-by: Adrian Junge (vurlo)
+
+CVE: CVE-2026-65704
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavformat/ty.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/libavformat/ty.c b/libavformat/ty.c
+index 596e4cc..1f2b6f8 100644
+--- a/libavformat/ty.c
++++ b/libavformat/ty.c
+@@ -577,7 +577,7 @@ static int demux_audio(AVFormatContext *s, TyRecHdr *rec_hdr, AVPacket *pkt)
+         if (ty->audio_type == TIVO_AUDIO_AC3 &&
+                 ty->tivo_series == TIVO_SERIES2) {
+             if (ty->ac3_pkt_size + pkt->size > AC3_PKT_LENGTH) {
+-                pkt->size -= 2;
++                pkt->size -= FFMIN(pkt->size, 2);
+                 ty->ac3_pkt_size = 0;
+             } else {
+                 ty->ac3_pkt_size += pkt->size;
+-- 
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 7f0cdd4577..da96d63219 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -31,6 +31,7 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
            file://CVE-2026-64834.patch \
            file://CVE-2026-64835.patch \
            file://CVE-2026-65703.patch \
+           file://CVE-2026-65704.patch \
            "
 
 SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
-- 
2.43.0

[wrynose][oe-core][PATCH 09/10] ffmpeg: Fix for CVE-2026-65705

From: <hidden>
Date: 2026-09-10 13:34:25

From: Bhavesh R Maheshwari <redacted>

Pick the patch from [1] and [2], mentioned in PR#23780 [3] which is
referenced in the NVD report [4]

[1] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/24c322fdb232d0a3f3790d544dcb64e5c2138e79
[2] https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c
[3] https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780
[4] https://nvd.nist.gov/vuln/detail/cve-2026-65705

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 .../ffmpeg/ffmpeg/CVE-2026-65705_p1.patch     |  68 +++++++++++
 .../ffmpeg/ffmpeg/CVE-2026-65705_p2.patch     | 115 ++++++++++++++++++
 .../recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb |   2 +
 3 files changed, 185 insertions(+)
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch
 create mode 100644 meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch
new file mode 100644
index 0000000000..e331cb9646
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p1.patch
@@ -0,0 +1,68 @@
+From f73f6cd9a5f230ce02afbc6a74172400b92b1127 Mon Sep 17 00:00:00 2001
+From: Michael Niedermayer <michael@niedermayer.cc>
+Date: Sat, 11 Jul 2026 16:47:28 +0200
+Subject: [PATCH 7/9] avfilter/vf_floodfill: size the point stack for the
+ current frame
+
+Fixes: out of array access
+Fixes: 8aj_floodfill_dynamic_size.pgm / 8aj_generate_floodfill_dynamic_size_pgm.py
+Fixes: 3MleMXjGZvu3
+Found-by: Adrian Junge (vurlo) <adjun37@gmail.com>
+
+CVE: CVE-2026-65705
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/24c322fdb232d0a3f3790d544dcb64e5c2138e79]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavfilter/vf_floodfill.c | 19 ++++++++++++++++---
+ 1 file changed, 16 insertions(+), 3 deletions(-)
+
+diff --git a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c
+index 6d89963..e569d5f 100644
+--- a/libavfilter/vf_floodfill.c
++++ b/libavfilter/vf_floodfill.c
+@@ -41,6 +41,7 @@ typedef struct FloodfillContext {
+     int nb_planes;
+     int back, front;
+     Points *points;
++    unsigned int points_size;
+ 
+     int (*is_same)(const AVFrame *frame, int x, int y,
+                    unsigned s0, unsigned s1, unsigned s2, unsigned s3);
+@@ -271,9 +272,6 @@ static int config_input(AVFilterLink *inlink)
+     }
+ 
+     s->front = s->back = 0;
+-    s->points = av_calloc(inlink->w * inlink->h, 4 * sizeof(Points));
+-    if (!s->points)
+-        return AVERROR(ENOMEM);
+ 
+     return 0;
+ }
+@@ -292,8 +290,23 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame)
+     int s3 = s->s[3];
+     const int w = frame->width;
+     const int h = frame->height;
++    size_t nb_points, points_size;
+     int i, ret;
+ 
++    if (w > UINT16_MAX + 1 || h > UINT16_MAX + 1 ||
++        av_size_mult(w, h, &nb_points) < 0 ||
++        av_size_mult(nb_points, 4 * sizeof(*s->points), &points_size) < 0) {
++        av_frame_free(&frame);
++        return AVERROR(EINVAL);
++    }
++
++    av_fast_malloc(&s->points, &s->points_size, points_size);
++    if (!s->points) {
++        av_frame_free(&frame);
++        return AVERROR(ENOMEM);
++    }
++    s->front = s->back = 0;
++
+     if (is_inside(s->x, s->y, w, h)) {
+         s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3);
+ 
+-- 
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch
new file mode 100644
index 0000000000..91a304015f
--- /dev/null
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg/CVE-2026-65705_p2.patch
@@ -0,0 +1,115 @@
+From 7f99588c7fc27526a2d73dddc91e4cd57a3b401c Mon Sep 17 00:00:00 2001
+From: Michael Niedermayer <michael@niedermayer.cc>
+Date: Sun, 12 Jul 2026 03:27:47 +0200
+Subject: [PATCH 8/9] avfilter/vf_floodfill: remove unneeded variables
+
+Signed-off-by: Michael Niedermayer <michael@niedermayer.cc>
+
+CVE: CVE-2026-65705
+Upstream-Status: Backport [https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c]
+
+Signed-off-by: Bhavesh R Maheshwari <bhavesh.maheshwari@einfochips.com>
+---
+ libavfilter/vf_floodfill.c | 35 ++++++++++++++++-------------------
+ 1 file changed, 16 insertions(+), 19 deletions(-)
+
+diff --git a/libavfilter/vf_floodfill.c b/libavfilter/vf_floodfill.c
+index e569d5f..9bc72e2 100644
+--- a/libavfilter/vf_floodfill.c
++++ b/libavfilter/vf_floodfill.c
+@@ -39,7 +39,6 @@ typedef struct FloodfillContext {
+     int d[4];
+ 
+     int nb_planes;
+-    int back, front;
+     Points *points;
+     unsigned int points_size;
+ 
+@@ -271,8 +270,6 @@ static int config_input(AVFilterLink *inlink)
+        }
+     }
+ 
+-    s->front = s->back = 0;
+-
+     return 0;
+ }
+ 
+@@ -292,6 +289,7 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame)
+     const int h = frame->height;
+     size_t nb_points, points_size;
+     int i, ret;
++    int front = 0;
+ 
+     if (w > UINT16_MAX + 1 || h > UINT16_MAX + 1 ||
+         av_size_mult(w, h, &nb_points) < 0 ||
+@@ -305,7 +303,6 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame)
+         av_frame_free(&frame);
+         return AVERROR(ENOMEM);
+     }
+-    s->front = s->back = 0;
+ 
+     if (is_inside(s->x, s->y, w, h)) {
+         s->pick_pixel(frame, s->x, s->y, &s0, &s1, &s2, &s3);
+@@ -323,9 +320,9 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame)
+             goto end;
+ 
+         if (s->is_same(frame, s->x, s->y, s0, s1, s2, s3)) {
+-            s->points[s->front].x = s->x;
+-            s->points[s->front].y = s->y;
+-            s->front++;
++            s->points[front].x = s->x;
++            s->points[front].y = s->y;
++            front++;
+         }
+ 
+         if (ret = ff_inlink_make_frame_writable(link, &frame)) {
+@@ -333,34 +330,34 @@ static int filter_frame(AVFilterLink *link, AVFrame *frame)
+             return ret;
+         }
+ 
+-        while (s->front > s->back) {
++        while (front > 0) {
+             int x, y;
+ 
+-            s->front--;
+-            x = s->points[s->front].x;
+-            y = s->points[s->front].y;
++            front--;
++            x = s->points[front].x;
++            y = s->points[front].y;
+ 
+             if (s->is_same(frame, x, y, s0, s1, s2, s3)) {
+                 s->set_pixel(frame, x, y, d0, d1, d2, d3);
+ 
+                 if (is_inside(x + 1, y, w, h)) {
+-                    s->points[s->front]  .x = x + 1;
+-                    s->points[s->front++].y = y;
++                    s->points[front]  .x = x + 1;
++                    s->points[front++].y = y;
+                 }
+ 
+                 if (is_inside(x - 1, y, w, h)) {
+-                    s->points[s->front]  .x = x - 1;
+-                    s->points[s->front++].y = y;
++                    s->points[front]  .x = x - 1;
++                    s->points[front++].y = y;
+                 }
+ 
+                 if (is_inside(x, y + 1, w, h)) {
+-                    s->points[s->front]  .x = x;
+-                    s->points[s->front++].y = y + 1;
++                    s->points[front]  .x = x;
++                    s->points[front++].y = y + 1;
+                 }
+ 
+                 if (is_inside(x, y - 1, w, h)) {
+-                    s->points[s->front]  .x = x;
+-                    s->points[s->front++].y = y - 1;
++                    s->points[front]  .x = x;
++                    s->points[front++].y = y - 1;
+                 }
+             }
+         }
+-- 
+2.43.0
+
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index da96d63219..36a9ae14f2 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -32,6 +32,8 @@ SRC_URI = "https://www.ffmpeg.org/releases/${BP}.tar.xz \
            file://CVE-2026-64835.patch \
            file://CVE-2026-65703.patch \
            file://CVE-2026-65704.patch \
+           file://CVE-2026-65705_p1.patch \
+           file://CVE-2026-65705_p2.patch \
            "
 
 SRC_URI[sha256sum] = "6136812ea6d4e68bdba27e33c2a94382711cdf4f8602ffef056ff792bd6f9818"
-- 
2.43.0

Re: [wrynose][oe-core][PATCH 02/10] ffmpeg: set CVE_STATUS for CVE-2026-64831

From: Yoann Congal <hidden>
Date: 2026-09-15 14:20:26

On Thu Sep 10, 2026 at 3:31 PM CEST, Bhavesh R Maheshwari via lists.openembedded.org wrote:
quoted hunk
From: Bhavesh R Maheshwari <redacted>

Analysis:
- CVE-2026-64831 affects Vulkan HEVC hardware acceleration.[1]
- The ffmpeg recipe does not enable or build Vulkan HEVC hardware acceleration by default.
- Hence CVE is not applicable.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-64831

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
 1 file changed, 1 insertion(+)
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 8c1969369b..af05ab4af9 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -186,3 +186,4 @@ CVE_STATUS[CVE-2025-59729] = "fixed-version: this CVE are fixed since v8.0"
 CVE_STATUS[CVE-2025-59730] = "fixed-version: this CVE are fixed since v8.0"
 CVE_STATUS[CVE-2026-8461] = "cpe-stable-backport: this CVE are fixed since v8.0.3"
 CVE_STATUS[CVE-2026-40962] = "cpe-stable-backport: this CVE are fixed since v8.0.2"
+CVE_STATUS[CVE-2026-64831] = "not-applicable-config: Vulkan HEVC hardware acceleration is not enabled or built by this recipe."
Hello,

Nothing prevent a downstream layer from activating this feature.

The CVE fix[0] (per NVD) is quite simple and does apply on the ffmpeg
8.0.x branch. Can you send a backport of the fix instead?

I'll keep reviewing the rest of the series.

[0]: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665/commits/ea8087200ce91f3f296a30541a89b19ae4af19a2

Thanks!
-- 
Yoann Congal
Smile ECS

Re: [wrynose][oe-core][PATCH 03/10] ffmpeg: set CVE_STATUS for CVE-2026-64832

From: Yoann Congal <hidden>
Date: 2026-09-15 14:24:05

On Thu Sep 10, 2026 at 3:31 PM CEST, Bhavesh R Maheshwari via lists.openembedded.org wrote:
quoted hunk
From: Bhavesh R Maheshwari <redacted>

Analysis:
- CVE-2026-64832 affects NVIDIA NVDEC hardware acceleration.[1]
- The ffmpeg recipe does not enable or build NVIDIA NVDEC hardware acceleration by default.
- Hence CVE is not applicable.

Reference:
[1] https://nvd.nist.gov/vuln/detail/CVE-2026-64832

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
 1 file changed, 1 insertion(+)
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index af05ab4af9..68f09c2bc4 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -187,3 +187,4 @@ CVE_STATUS[CVE-2025-59730] = "fixed-version: this CVE are fixed since v8.0"
 CVE_STATUS[CVE-2026-8461] = "cpe-stable-backport: this CVE are fixed since v8.0.3"
 CVE_STATUS[CVE-2026-40962] = "cpe-stable-backport: this CVE are fixed since v8.0.2"
 CVE_STATUS[CVE-2026-64831] = "not-applicable-config: Vulkan HEVC hardware acceleration is not enabled or built by this recipe."
+CVE_STATUS[CVE-2026-64832] = "not-applicable-config: NVIDIA NVDEC hardware acceleration is not enabled or built by this recipe."
Same as 2/10.

Regards,
-- 
Yoann Congal
Smile ECS

Re: [External] Re: [wrynose][oe-core][PATCH 02/10] ffmpeg: set CVE_STATUS for CVE-2026-64831

From: Bhavesh Rajesh Maheshwari <hidden>
Date: 2026-09-15 15:06:38

Hi Yoann,

Thanks for the update. Request you to drop the whole series, will send you the updated series soon.

Thanks
Bhavesh Maheshwari

Thanks and Regards,
Bhavesh Maheshwari
Engineer
+91-8827543501

________________________________
From: openembedded-core@lists.openembedded.org <redacted> on behalf of Yoann Congal via lists.openembedded.org <yoann.congal=smile.fr@lists.openembedded.org>
Sent: Tuesday, 15 September 2026 19:50:20
To: Bhavesh Rajesh Maheshwari <redacted>; openembedded-core@lists.openembedded.org <redacted>
Subject: [External] Re: [wrynose][oe-core][PATCH 02/10] ffmpeg: set CVE_STATUS for CVE-2026-64831


CAUTION: This email originated from outside of the organization. This message might not be safe, use caution in opening it. If in doubt, do not open the attachment nor links in the message.


On Thu Sep 10, 2026 at 3:31 PM CEST, Bhavesh R Maheshwari via lists.openembedded.org wrote:
quoted hunk
From: Bhavesh R Maheshwari <redacted>

Analysis:
- CVE-2026-64831 affects Vulkan HEVC hardware acceleration.[1]
- The ffmpeg recipe does not enable or build Vulkan HEVC hardware acceleration by default.
- Hence CVE is not applicable.

Reference:
[1] https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnvd.nist.gov%2Fvuln%2Fdetail%2FCVE-2026-64831&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C41484021a46a4dfe47bf08df13347c8e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639250788317922015%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=yrPdD%2BheY4S%2BI%2Blk9W25PQl%2B48IbR6hDqkjhzHwdD38%3D&reserved=0<https://nvd.nist.gov/vuln/detail/CVE-2026-64831>

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
 1 file changed, 1 insertion(+)
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 8c1969369b..af05ab4af9 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -186,3 +186,4 @@ CVE_STATUS[CVE-2025-59729] = "fixed-version: this CVE are fixed since v8.0"
 CVE_STATUS[CVE-2025-59730] = "fixed-version: this CVE are fixed since v8.0"
 CVE_STATUS[CVE-2026-8461] = "cpe-stable-backport: this CVE are fixed since v8.0.3"
 CVE_STATUS[CVE-2026-40962] = "cpe-stable-backport: this CVE are fixed since v8.0.2"
+CVE_STATUS[CVE-2026-64831] = "not-applicable-config: Vulkan HEVC hardware acceleration is not enabled or built by this recipe."
Hello,

Nothing prevent a downstream layer from activating this feature.

The CVE fix[0] (per NVD) is quite simple and does apply on the ffmpeg
8.0.x branch. Can you send a backport of the fix instead?

I'll keep reviewing the rest of the series.

[0]: https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fpulls%2F23665%2Fcommits%2Fea8087200ce91f3f296a30541a89b19ae4af19a2&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C41484021a46a4dfe47bf08df13347c8e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639250788317952327%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Svy41Azt9Tq9hacdbW%2BYKDW6HUUQGxDJ7n%2FWQKoUaus%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665/commits/ea8087200ce91f3f296a30541a89b19ae4af19a2>

Thanks!
--
Yoann Congal
Smile ECS

Re: [External] Re: [wrynose][oe-core][PATCH 02/10] ffmpeg: set CVE_STATUS for CVE-2026-64831

From: Bhavesh Rajesh Maheshwari <hidden>
Date: 2026-09-16 09:22:55

Hello Yoann,
Thanks for the review.
I agree that a downstream layer could enable Vulkan HEVC hardware acceleration. However, by default this configuration is not enabled or built by the ffmpeg recipe.
Since the affected Vulkan HEVC code is not built with the default recipe configuration, the proposed fix would not be compiled or exercised in our default build.
Could we instead handle this using a conditional CVE_STATUS, so that the CVE is marked as not applicable when Vulkan HEVC hardware acceleration is not enabled, while still allowing the CVE to be reported when the relevant configuration is enabled by a downstream layer?

Thanks,

Bhavesh Maheshwari
Engineer
+91 8827543501
Bhavesh.Maheshwari@einfochips.com<mailto:Bhavesh.Maheshwari@einfochips.com>
[cid:d82e07d2-bdd2-4ad9-b5ee-cc155ce89991]<https://www.einfochips.com/>
________________________________
From: openembedded-core@lists.openembedded.org <redacted> on behalf of Yoann Congal via lists.openembedded.org <yoann.congal=smile.fr@lists.openembedded.org>
Sent: 15 September 2026 19:50
To: Bhavesh Rajesh Maheshwari <redacted>; openembedded-core@lists.openembedded.org <redacted>
Subject: [External] Re: [wrynose][oe-core][PATCH 02/10] ffmpeg: set CVE_STATUS for CVE-2026-64831


CAUTION: This email originated from outside of the organization. This message might not be safe, use caution in opening it. If in doubt, do not open the attachment nor links in the message.


On Thu Sep 10, 2026 at 3:31 PM CEST, Bhavesh R Maheshwari via lists.openembedded.org wrote:
quoted hunk
From: Bhavesh R Maheshwari <redacted>

Analysis:
- CVE-2026-64831 affects Vulkan HEVC hardware acceleration.[1]
- The ffmpeg recipe does not enable or build Vulkan HEVC hardware acceleration by default.
- Hence CVE is not applicable.

Reference:
[1] https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnvd.nist.gov%2Fvuln%2Fdetail%2FCVE-2026-64831&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C41484021a46a4dfe47bf08df13347c8e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639250788317922015%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=yrPdD%2BheY4S%2BI%2Blk9W25PQl%2B48IbR6hDqkjhzHwdD38%3D&reserved=0<https://nvd.nist.gov/vuln/detail/CVE-2026-64831>

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
 1 file changed, 1 insertion(+)
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 8c1969369b..af05ab4af9 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -186,3 +186,4 @@ CVE_STATUS[CVE-2025-59729] = "fixed-version: this CVE are fixed since v8.0"
 CVE_STATUS[CVE-2025-59730] = "fixed-version: this CVE are fixed since v8.0"
 CVE_STATUS[CVE-2026-8461] = "cpe-stable-backport: this CVE are fixed since v8.0.3"
 CVE_STATUS[CVE-2026-40962] = "cpe-stable-backport: this CVE are fixed since v8.0.2"
+CVE_STATUS[CVE-2026-64831] = "not-applicable-config: Vulkan HEVC hardware acceleration is not enabled or built by this recipe."
Hello,

Nothing prevent a downstream layer from activating this feature.

The CVE fix[0] (per NVD) is quite simple and does apply on the ffmpeg
8.0.x branch. Can you send a backport of the fix instead?

I'll keep reviewing the rest of the series.

[0]: https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fpulls%2F23665%2Fcommits%2Fea8087200ce91f3f296a30541a89b19ae4af19a2&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C41484021a46a4dfe47bf08df13347c8e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639250788317952327%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Svy41Azt9Tq9hacdbW%2BYKDW6HUUQGxDJ7n%2FWQKoUaus%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665/commits/ea8087200ce91f3f296a30541a89b19ae4af19a2>

Thanks!
--
Yoann Congal
Smile ECS

Re: [External] Re: [wrynose][oe-core][PATCH 02/10] ffmpeg: set CVE_STATUS for CVE-2026-64831

From: Yoann Congal <hidden>
Date: 2026-09-16 10:22:16

On Wed Sep 16, 2026 at 11:22 AM CEST, Bhavesh Rajesh Maheshwari wrote:
Hello Yoann,
Thanks for the review.
I agree that a downstream layer could enable Vulkan HEVC hardware
acceleration. However, by default this configuration is not enabled or
built by the ffmpeg recipe.
Since the affected Vulkan HEVC code is not built with the default
recipe configuration, the proposed fix would not be compiled or
exercised in our default build.
Yes, that's understood.
Could we instead handle this using a conditional CVE_STATUS, so that
the CVE is marked as not applicable when Vulkan HEVC hardware
acceleration is not enabled, while still allowing the CVE to be
reported when the relevant configuration is enabled by a downstream
layer?
In this case, the patch is really simple. So it can be reviewed by
reading it.

And, while, yes it would not be compiled during our process. It would be
on the code-path of downstream users that would activate vulkan. Then,
in case of an issue, they can review/notify us/send fixes.

Conditionnal CVE_STATUS are not a desirable outcome and more a
"last-resort" kind of thing: Here, I don't think this is worth it.

Let's backport the patch instead.

Thanks!
Thanks,

Bhavesh Maheshwari
Engineer
+91 8827543501
Bhavesh.Maheshwari@einfochips.com<mailto:Bhavesh.Maheshwari@einfochips.com>
[cid:d82e07d2-bdd2-4ad9-b5ee-cc155ce89991]<https://www.einfochips.com/>
________________________________
From: openembedded-core@lists.openembedded.org <redacted> on behalf of Yoann Congal via lists.openembedded.org <yoann.congal=smile.fr@lists.openembedded.org>
Sent: 15 September 2026 19:50
To: Bhavesh Rajesh Maheshwari <redacted>; openembedded-core@lists.openembedded.org <redacted>
Subject: [External] Re: [wrynose][oe-core][PATCH 02/10] ffmpeg: set CVE_STATUS for CVE-2026-64831


CAUTION: This email originated from outside of the organization. This message might not be safe, use caution in opening it. If in doubt, do not open the attachment nor links in the message.


On Thu Sep 10, 2026 at 3:31 PM CEST, Bhavesh R Maheshwari via lists.openembedded.org wrote:
quoted
From: Bhavesh R Maheshwari <redacted>

Analysis:
- CVE-2026-64831 affects Vulkan HEVC hardware acceleration.[1]
- The ffmpeg recipe does not enable or build Vulkan HEVC hardware acceleration by default.
- Hence CVE is not applicable.

Reference:
[1] https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fnvd.nist.gov%2Fvuln%2Fdetail%2FCVE-2026-64831&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C41484021a46a4dfe47bf08df13347c8e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639250788317922015%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=yrPdD%2BheY4S%2BI%2Blk9W25PQl%2B48IbR6hDqkjhzHwdD38%3D&reserved=0<https://nvd.nist.gov/vuln/detail/CVE-2026-64831>

Signed-off-by: Bhavesh R Maheshwari <redacted>
---
 meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb | 1 +
 1 file changed, 1 insertion(+)
diff --git a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
index 8c1969369b..af05ab4af9 100644
--- a/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
+++ b/meta/recipes-multimedia/ffmpeg/ffmpeg_8.0.3.bb
@@ -186,3 +186,4 @@ CVE_STATUS[CVE-2025-59729] = "fixed-version: this CVE are fixed since v8.0"
 CVE_STATUS[CVE-2025-59730] = "fixed-version: this CVE are fixed since v8.0"
 CVE_STATUS[CVE-2026-8461] = "cpe-stable-backport: this CVE are fixed since v8.0.3"
 CVE_STATUS[CVE-2026-40962] = "cpe-stable-backport: this CVE are fixed since v8.0.2"
+CVE_STATUS[CVE-2026-64831] = "not-applicable-config: Vulkan HEVC hardware acceleration is not enabled or built by this recipe."
Hello,

Nothing prevent a downstream layer from activating this feature.

The CVE fix[0] (per NVD) is quite simple and does apply on the ffmpeg
8.0.x branch. Can you send a backport of the fix instead?

I'll keep reviewing the rest of the series.

[0]: https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fcode.ffmpeg.org%2FFFmpeg%2FFFmpeg%2Fpulls%2F23665%2Fcommits%2Fea8087200ce91f3f296a30541a89b19ae4af19a2&data=05%7C02%7Cbhavesh.maheshwari%40einfochips.com%7C41484021a46a4dfe47bf08df13347c8e%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C639250788317952327%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Svy41Azt9Tq9hacdbW%2BYKDW6HUUQGxDJ7n%2FWQKoUaus%3D&reserved=0<https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665/commits/ea8087200ce91f3f296a30541a89b19ae4af19a2>

Thanks!
--
Yoann Congal
Smile ECS

-- 
Yoann Congal
Smile ECS

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help