CVE-2026-66038: FFmpeg LCL/ZLIB Video Decoder Information Disclosure via lcldec.c

Published Jul 24, 2026
·
Updated

FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlibdecomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services.

Affected Software

1 affected component
FFmpeg FFmpeg<=8.1.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FFmpeg LCL/ZLIB video decoder (lcldec.c) to a version that resolves this vulnerability.

    Fixed in commit 8670835Patch 8670835

Event History

Jul 24, 2026
CVE Published
via MITRE·07:39 PM
Data Sourced
via MITRE·07:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:18 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-66038?

CVE-2026-66038 has a medium severity rating with a score of 6.5.

2

How do I fix CVE-2026-66038?

To fix CVE-2026-66038, you should update FFmpeg to version 8.1.3 or later, where the vulnerability has been patched.

3

What kind of vulnerability is CVE-2026-66038?

CVE-2026-66038 is an information disclosure vulnerability in the LCL/ZLIB video decoder of FFmpeg.

4

What does CVE-2026-66038 affect?

CVE-2026-66038 affects FFmpeg versions up to 8.1.2.

5

What can attackers do with CVE-2026-66038?

Attackers can exploit CVE-2026-66038 to expose uninitialized heap memory by supplying a valid zlib stream.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203