Executive brief
FFmpeg, a widely used multimedia framework for processing video and audio, contains a flaw in its LCL/ZLIB video decoder. An attacker can exploit this by providing a specially crafted video file that, when processed, reveals sensitive information from the system's memory. This could allow an attacker to bypass security protections like ASLR or access data from other tasks handled by the same media service.
Technical details
An information disclosure vulnerability exists in the FFmpeg LCL/ZLIB video decoder within the zlib_decomp() function in lcldec.c. The function fails to treat short decompression (where the zlib stream inflates to fewer bytes than the expected frame size) as a fatal error. Consequently, the decoder proceeds to the RGB24 conversion path, which copies a full frame's worth of data from the allocation buffer based on original dimensions. This results in uninitialized heap memory, potentially containing pointer-derived allocator bytes, being copied into the attacker-observable AVFrame output. This can be used to defeat ASLR in long-lived media processing services. The issue is fixed in commit 8670835 (and e7cbfd1c50) by zeroing the non-decoded tail of the buffer.
Affected products
- FFmpeg FFmpeg through 8.1.2
Timeline
- 2026-06-28: patched: Initial patch commit authored
- 2026-07-05: other: Patch merged into master branch
- 2026-07-24: advisory: NVD publication date