FFmpeg disclosed and patched CVE-2026-70628, a high-severity heap buffer overflow in the DVB subtitle parser within libavcodec/dvbsub_parser.c that affects versions 0.5 through before 9.0. The flaw stems from a signed integer overflow in a capacity check: a crafted WTV file can force the bounds-check expression to wrap to INT_MIN, bypass the PARSE_BUF_SIZE validation, and trigger an out-of-bounds heap write through memcpy(). The resulting memory corruption could potentially be leveraged for code execution when malicious media is processed.
The issue is tracked under CWE-190 and CWE-787 and was addressed through FFmpeg commits and pull request #23897, which changed avcodec/dvbsub_parser to avoid signed overflow in the capacity check. The vulnerable code path traces back to the long-standing DVB subtitle decoder implementation, indicating broad version exposure across FFmpeg deployments that ingest untrusted broadcast or recorded video content.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
A new CVE entry, CVE-2026-70628, was received on August 6, 2026 for FFmpeg versions 0.5 through before 9.0. The record describes a signed integer overflow in libavcodec/dvbsub_parser.c where a crafted WTV file can bypass a bounds check and trigger an out-of-bounds heap write via memcpy().
FFmpeg opened pull request 23897 for "avcodec/dvbsub_parser: avoid signed overflow in the capacity check." The CVE record later referenced this pull request as part of the remediation for the vulnerability.
FFmpeg published commits 02fc47e13f903768b75f7985a2706a6223ab4506 and 93f2a525ec6c7b467bae68322720d10188fc6e30 titled "avoid signed overflow in the capacity check" for avcodec/dvbsub_parser. These commits correspond to the fix for the heap buffer overflow issue later tracked as CVE-2026-70628.
FFmpeg introduced the DVB subtitle decoder code in commit c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c. The later CVE record identifies the DVB subtitle parser in this code path as the vulnerable component.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecode.ffmpeg.org
Open sourcecode.ffmpeg.org
Open sourcecode.ffmpeg.org
Open sourcecode.ffmpeg.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.