JLSEC-2026-1191

Source
https://github.com/JuliaLang/SecurityAdvisories.jl/blob/main/advisories/published/2026/JLSEC-2026-1191.md
Import Source
https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1191.json
JSON Data
https://api.osv.dev/v1/vulns/JLSEC-2026-1191
Upstream
  • CVE-2026-70631
  • EUVD-2026-54164
  • GHSA-5f73-3r3j-p8mr
Published
2026-08-07T13:27:45.313Z
Modified
2026-08-07T13:43:40.901565465Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
  • 6.8 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory...
Details

FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services.

Database specific
{
    "sources": [
        {
            "modified": "2026-08-06T22:18:27.420Z",
            "database_specific": {
                "status": "Received"
            },
            "id": "CVE-2026-70631",
            "html_url": "https://nvd.nist.gov/vuln/detail/CVE-2026-70631",
            "url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-70631",
            "imported": "2026-08-07T05:41:28.789Z",
            "published": "2026-08-06T22:18:27.420Z"
        },
        {
            "modified": "2026-08-07T00:31:27Z",
            "html_url": "https://github.com/advisories/GHSA-5f73-3r3j-p8mr",
            "id": "GHSA-5f73-3r3j-p8mr",
            "url": "https://api.github.com/advisories/GHSA-5f73-3r3j-p8mr",
            "imported": "2026-08-07T05:42:30.591Z",
            "published": "2026-08-07T00:31:21Z"
        },
        {
            "modified": "2026-08-06T21:27:47Z",
            "html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-54164",
            "id": "EUVD-2026-54164",
            "url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2026-54164",
            "imported": "2026-08-07T05:41:14.856Z",
            "published": "2026-08-06T21:25:53Z"
        }
    ],
    "license": "CC-BY-4.0"
}
References

Affected packages

Julia / FFMPEG_jll

Package

Name
FFMPEG_jll
Purl
pkg:julia/FFMPEG_jll?uuid=b22a6f82-2f65-5046-a5b2-351ab43fb4e5

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.0.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1191.json"

Julia / FFMPEG_nogpl_jll

Package

Name
FFMPEG_nogpl_jll
Purl
pkg:julia/FFMPEG_nogpl_jll?uuid=a6892c6b-5768-548c-b024-ff8dabf482c5

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
9.0.0+0

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1191.json"

Julia / FFplay_jll

Package

Name
FFplay_jll
Purl
pkg:julia/FFplay_jll?uuid=c4dce911-e170-5107-8314-c7bdc6785395

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-1191.json"