CVE-2026-66038

EUVD-2026-48740
FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 15.29%
Affected Products (NVD)
VendorProductVersion
ffmpegffmpeg
𝑥
≤ 8.1.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
ffmpeg
bookworm
vulnerable
bookworm (security)
vulnerable
forky
vulnerable
sid
vulnerable
trixie
postponed
trixie (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
ffmpeg
bionic
Fixed 7:3.4.11-0ubuntu0.1+esm13
released
focal
Fixed 7:4.2.7-0ubuntu0.1+esm14
released
jammy
Fixed 7:4.4.2-0ubuntu0.22.04.1+esm13
released
noble
Fixed 7:6.1.1-3ubuntu5+esm11
released
resolute
needed
xenial
Fixed 7:2.8.17-0ubuntu0.1+esm15
released
libav
jammy
dne
noble
dne
resolute
dne
trusty
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libavcodec58_134
suse enterprise desktop 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise sap 15 SP4
4.4.8-150400.3.72.1
fixed
suse enterprise sap 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise server 15 SP4
4.4.8-150400.3.72.1
fixed
suse enterprise server 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise workstation 15 SP7
4.4.8-150600.13.52.1
fixed
libavformat58_76
suse enterprise desktop 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise sap 15 SP4
4.4.8-150400.3.72.1
fixed
suse enterprise sap 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise server 15 SP4
4.4.8-150400.3.72.1
fixed
suse enterprise server 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise workstation 15 SP7
4.4.8-150600.13.52.1
fixed
libavutil56_70
suse enterprise desktop 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise sap 15 SP4
4.4.8-150400.3.72.1
fixed
suse enterprise sap 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise server 15 SP4
4.4.8-150400.3.72.1
fixed
suse enterprise server 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise workstation 15 SP7
4.4.8-150600.13.52.1
fixed
libpostproc55_9
suse enterprise sap 15 SP4
4.4.8-150400.3.72.1
fixed
suse enterprise server 15 SP4
4.4.8-150400.3.72.1
fixed
libswresample3_9
suse enterprise desktop 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise sap 15 SP4
4.4.8-150400.3.72.1
fixed
suse enterprise sap 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise server 15 SP4
4.4.8-150400.3.72.1
fixed
suse enterprise server 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise workstation 15 SP7
4.4.8-150600.13.52.1
fixed
libswscale5_9
suse enterprise desktop 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise sap 15 SP4
4.4.8-150400.3.72.1
fixed
suse enterprise sap 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise server 15 SP4
4.4.8-150400.3.72.1
fixed
suse enterprise server 15 SP7
4.4.8-150600.13.52.1
fixed
suse enterprise workstation 15 SP7
4.4.8-150600.13.52.1
fixed