PT-2026-64414 · FFmpeg+3 · Ffmpeg+3

·

CVE-2026-66038

·

Published

2026-07-24

·

Updated

2026-09-08

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions FFmpeg versions prior to 8.1.2
Description An information disclosure issue exists in the LCL/ZLIB video decoder. An attacker can expose uninitialized heap memory by providing a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib decomp() function in lcldec.c treats short decompression as non-fatal and proceeds to the RGB24 conversion path. This process copies a full frame of rows from the allocation buffer based on original frame dimensions, resulting in uninitialized heap contents, such as pointer-derived allocator bytes, being copied into the AVFrame output. This could potentially defeat Address Space Layout Randomization (ASLR), a security technique that randomly arranges the address space positions of key data areas of a process to prevent exploitation.
Recommendations Update FFmpeg to the version containing commit 8670835.

Exploit

Fix

DoS

Use of Uninitialized Resource

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66038
ECHO-9DB0-DFD3-A7BB
JLSEC-2026-1184
OESA-2026-3542
OESA-2026-3543
OESA-2026-3544
OPENSUSE-SU-2026:11448-1
OPENSUSE-SU-2026:11665-1
OPENSUSE-SU-2026:21522-1
OPENSUSE-SU-2026:21572-1
SUSE-SU-2026:23222-1
SUSE-SU-2026:23232-1
SUSE-SU-2026:3529-1
SUSE-SU-2026:3542-1
USN-8671-1
USN-8738-1

Affected Products

Ffmpeg
Linuxmint
Red Os
Ubuntu