Skip to content
VulniPulse
Highest advisory severityMedium 1 vendor · 1 advisory

CVE-2026-66038

CVE-2026-66038: 1 tracked advisory record across Red Hat. Compare source-reported impact, fixes and remediation.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityMedium6.5

    Medium [CVE-2026-66038] Information disclosure via malformed zlib video stream

    CVE-2026-66038Source published Source updated

    FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers to expose uninitialized heap memory by supplying a valid zlib stream that inflates to fewer bytes than the expected frame size. The zlib_decomp() function in lcldec.c treats short decompression as non-fatal and continues to the RGB24 conversion path, which copies a full frame's worth of rows from the allocation buffer using original frame dimensions, causing uninitialized heap contents including pointer-derived allocator bytes to be copied into the attacker-observable AVFrame output and potentially defeating ASLR in long-lived media processing services. A remote attacker could exploit this vulnerability by providing a specially crafted zlib…

    Affected products in this advisory
    • Red Hat Enterprise Linux AI (RHEL AI) 3
    • Red Hat OpenShift AI (RHOAI)
    Source-reported affected versions
    Affected-version details not available in this record.
    Source-reported fixed versions
    • 8.1.2
    Mitigation guidance
    • To mitigate this issue, services utilizing FFmpeg for LCL/ZLIB video stream decoding should avoid returning raw, decoded frame data to untrusted external endpoints. Implement robust input validation for all video streams processed by such services. Additionally, consider sandboxing FFmpeg processes that handle untrusted video content to limit potential information exposure.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery