| Name | CVE-2026-13858 |
| Description | Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file. (Chromium security severity: Medium) |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| References | DLA-4672-1, DSA-6361-1, DSA-6378-1 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| chromium (PTS) | bookworm | 150.0.7871.100-1~deb12u1 | fixed |
| bookworm (security) | 153.0.8010.52-1~deb12u1 | fixed | |
| trixie | 150.0.7871.181-1~deb13u1 | fixed | |
| trixie (security) | 153.0.8010.52-1~deb13u1 | fixed | |
| forky | 150.0.7871.181-1 | fixed | |
| sid | 153.0.8010.52-1 | fixed | |
| ffmpeg (PTS) | bookworm, bookworm (security) | 7:5.1.9-0+deb12u1 | vulnerable |
| trixie (security), trixie | 7:7.1.5-0+deb13u1 | fixed | |
| forky | 7:8.1.2-2 | vulnerable | |
| sid | 7:9.0.2-1 | vulnerable |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| chromium | source | bullseye | (unfixed) | end-of-life | ||
| chromium | source | bookworm | 150.0.7871.46-1~deb12u1 | DLA-4672-1 | ||
| chromium | source | trixie | 150.0.7871.46-1~deb13u1 | DSA-6378-1 | ||
| chromium | source | (unstable) | 150.0.7871.46-1 | |||
| ffmpeg | source | trixie | 7:7.1.5-0+deb13u1 | DSA-6361-1 | ||
| ffmpeg | source | (unstable) | (unfixed) |
[bullseye] - chromium <end-of-life> (see #1061268)
[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
https://issues.chromium.org/issues/507090179
https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22976
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/256d93413f260e1524c2ab994dc72c4edaa0d04c (n9.0)
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cb8a5ca8ab36884064ac4de5175ae82c93edfcb2 (n7.1.5)