CVE-2026-90816
Publication date 14 September 2026
Last updated 17 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A vulnerability was found in FFmpeg 8.0.x. This affects the function parse_playlist of the file libavformat/hlsproto.c of the component Duration Parser. Performing a manipulation of the argument duration/target_duration results in denial of service. The attack is possible to be carried out remotely. Upgrading to version 8.1 and 9.0 is able to mitigate this issue. The patch is named 64fafd63f0b4. Upgrading the affected component is recommended.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| ffmpeg | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| libav | 26.04 LTS resolute | Not in release |
| 24.04 LTS noble | Not in release | |
| 22.04 LTS jammy | Not in release | |
| 14.04 LTS trusty |
Needs evaluation
|
Severity score breakdown
CVSS version:
Base score
5.3 · Medium
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Base score
4.3 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-90816
- https://code.ffmpeg.org/FFmpeg/FFmpeg/issues/21492
- https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/64fafd63f0b4ebf8dbbdbdc2296f21a03548b5fc (n8.1)
- https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/64fafd63f0b4
- https://ffmpeg.org/
- https://vuldb.com/cve/CVE-2026-90816
- https://vuldb.com/submit/922626
- https://vuldb.com/vuln/403318
- https://vuldb.com/vuln/403318/cti