JLSEC-2026-1184

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-1184.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1184.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-1184
Upstream
  • EUVD-2026-48740
  • GHSA-8mx4-8xfc-qr43
Published
2026-08-07T13:27:45.313Z
Modified
2026-08-07T13:43:41.171515894Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability...
Details

FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services.

Database specific
{
    "license": "CC-BY-4.0",
    "sources": [
        {
            "database_specific": {
                "status": "Analyzed"
            },
            "modified": "2026-08-07T00:54:32.767Z",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-66038",
            "published": "2026-07-24T20:18:20.727Z",
            "id": "CVE-2026-66038",
            "imported": "2026-08-07T05:41:14.749Z",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-66038"
        },
        {
            "modified": "2026-07-24T21:32:28Z",
            "url": "https://api.github.com/advisories/GHSA-8mx4-8xfc-qr43",
            "published": "2026-07-24T21:32:22Z",
            "id": "GHSA-8mx4-8xfc-qr43",
            "imported": "2026-08-07T05:42:30.745Z",
            "html_url": "https://github.com/advisories/GHSA-8mx4-8xfc-qr43"
        },
        {
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-48740",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-48740",
            "published": "2026-07-24T19:39:27Z",
            "id": "EUVD-2026-48740",
            "imported": "2026-08-07T05:41:15.362Z",
            "modified": "2026-07-28T01:06:28Z"
        }
    ]
}
References

Affected packages

Julia / FFMPEG_jll

Package

Name
FFMPEG_jll
Purl
pkg:julia/FFMPEG_jll?uuid=b22a6f82-2f65-5046-a5b2-351ab43fb4e5

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.0.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1184.json"

Julia / FFMPEG_nogpl_jll

Package

Name
FFMPEG_nogpl_jll
Purl
pkg:julia/FFMPEG_nogpl_jll?uuid=a6892c6b-5768-548c-b024-ff8dabf482c5

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.0.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1184.json"

Julia / FFplay_jll

Package

Name
FFplay_jll
Purl
pkg:julia/FFplay_jll?uuid=c4dce911-e170-5107-8314-c7bdc6785395

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1184.json"