A vulnerability was found in FFmpeg up to 8.1.2. It has been classified as critical. Impacted is the function
vk_hevc_end_frame of the component Vulkan HEVC hardware decoder. This manipulation of the argument vps_num_hrd_parameters causes stack-based buffer overflow.
This vulnerability is tracked as CVE-2026-64831. The attack is possible to be carried out remotely. No exploit exists.