What is CVE-2026-66038?
CVE-2026-66038 is an information disclosure vulnerability in the LCL/ZLIB video decoder of FFmpeg up to version 8.1.2. Attackers can expose uninitialized heap memory by providing a valid zlib stream that decompresses to fewer bytes than expected. Users should update to the fixed commit 8670835 to mitigate this issue.
Azərbaycanca: CVE-2026-66038, FFmpeg-in 8.1.2 versiyasına qədər olan LCL/ZLIB video decoder-ində aşkar edilmiş məlumat sızması zəifliyidir. Təcavüzkar xüsusi hazırlanmış zlib stream-i ilə heap yaddaşındakı ilkinləşdirilməmiş məlumatları oxuya bilər. İstifadəçilər commit 8670835 ilə düzəldilən bu problemi aradan qaldırmaq üçün FFmpeg-i yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which component of FFmpeg is affected by CVE-2026-66038?
CVE-2026-66038 is an information disclosure vulnerability found in the LCL/ZLIB video decoder of FFmpeg up to version 8.1.2.
What action should be taken to mitigate CVE-2026-66038?
Users should update to the fixed commit 8670835 to mitigate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.