suse · CVE-2026-40962

Quick triage

Priority: medium Published: 2026-04-17 13:50:13 UTC Updated: 2026-04-17 13:50:13 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2026-40962 severity moderate: SUSE including 29 source package names (ffmpeg, ffmpeg-private-devel, …), 194 product×package rows across 16 product lines (SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS, SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS, … (16 product lines)): Known Not Affected 194.

Description:

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

cvelogic Threat Intelligence