Bug 2512210 (CVE-2026-70631) - CVE-2026-70631 FFmpeg: FFmpeg: Information disclosure via uninitialized heap memory read in TIFF decoder
Summary: CVE-2026-70631 FFmpeg: FFmpeg: Information disclosure via uninitialized heap ...
Keywords:
Status: NEW
Alias: CVE-2026-70631
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2516040 2516041 2516042 2516043 2516047
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-06 22:22 UTC by OSIDB Bzimport
Modified: 2026-08-14 15:05 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-06 22:22:21 UTC
FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in libavcodec/tiff.c. An attacker who can cause FFmpeg to decode a crafted TIFF file can supply a valid Deflate-compressed strip that terminates successfully after producing fewer bytes than the declared strip requires. The tiff_unpack_zlib() function allocates a heap buffer sized for the full declared strip but copies all declared rows via memcpy() regardless of how many bytes zlib actually decompressed, causing unwritten bytes that can contain stale data from prior heap allocations to be incorporated into decoded image output and potentially exposing sensitive data in persistent services.


Note You need to log in before you can comment on or make changes to this bug.