# FFmpeg 4.4.8 — n4.4.8 - Product: FFmpeg (https://whatsnew.fyi/product/ffmpeg) - Vendor: FFmpeg - Date: 2026-06-21 - Version: 4.4.8 - Original notes: https://github.com/FFmpeg/FFmpeg/releases/tag/n4.4.8 - Permalink: https://whatsnew.fyi/product/ffmpeg/releases/4.4.8 - Labels: Machine-generated from commit messages — the vendor published no release notes What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **fixed** — HEVC decoder issues including missing-ref fill limiting to coded planes, window parameter validation, and NAL layer ID filtering. - **fixed** — Dirac decoder heap buffer overflow in edge_emu_buffer and mctmp row coverage. - **fixed** — Multiple integer overflow and signed overflow vulnerabilities in audio and video codecs including fastaudio, adpcm, on2avc, truespeech, and vc2enc_dwt. - **fixed** — Buffer overflow and bounds checking issues in various demuxers including matroska, mov, flac, vqf, and nuv. - **fixed** — JPEG2000 decoder issues including mask computation in decode_clnpass, header variable clearing, and lowres option handling. - **fixed** — RTP payload validation in rtpenc_aac, rtpenc_xiph, and rtpenc_amr to reject invalid packet sizes. - **fixed** — Format string and injection vulnerabilities in FTP demuxer for CR/LF in URL path and HTTP for unterminated request-line tokens. - **fixed** — Scale and filter issues including off-by-one in boxblur, uyvytoyuv422 overwrite on odd width, and subsampled alpha plane overread. - **fixed** — Memory safety issues in wave metadata chunks, MagicYUV slice validation, drawtext glyph deallocation, and stereotools buffer sizing. - **fixed** — H.264 and H.265 parsing issues including color_frame chroma-width underflow protection and mmco_reset input length validation.