CVE-2026-56711
published 2026-09-09CVE-2026-56711: VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user…
PriorityP432high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
EPSS
0.12%
1.7th percentile
VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| videolan | vlc_media_player | 3.0.0 – 3.0.23 | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv4.07.3HIGHCVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
vlc: VLC media player: Arbitrary code execution via integer overflow in picture allocation
vendor_redhat·2026-09-09·CVSS 8.8
CVE-2026-56711 [HIGH] CWE-787 vlc: VLC media player: Arbitrary code execution via integer overflow in picture allocation
vlc: VLC media player: Arbitrary code execution via integer overflow in picture allocation
A flaw was found in VLC media player. An integer overflow vulnerability exists when computing the size of a picture buffer, specifically in the AllocatePicture function. A remote attacker could exploit this by providing a specially crafted Portable Network Graphics (PNG) image file with large width and height dimensions. This leads to an undersized memory allocation, allowing the decoder to write past the end of the allocated buffer. This heap out-of-bounds write can result in arbitrary code execution.
Statement: Red Hat does not ship VLC media player in any Red Hat product. VLC is available in Fedora and EPEL community repositories and is affected in versions 3.0.0 through 3.0.23.
Mitigation: Mit
GHSA
VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result.
ghsa_unreviewed·2026-09-09
CVE-2026-56711 [HIGH] CWE-190 VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result.
VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result. In AllocatePicture in src/misc/picture.c the running total is accumulated as i_bytes += p->i_pitch * p->i_lines, and both plane_t fields are declared int in include/vlc_picture.h, so the multiplication is evaluated at 32 bits and wraps before it is widened to the size_t accumulator. The overflow check that precedes it divides in 64-bit arithmetic and therefore does not constrain the product, and the subsequent comparison against PICTURE_SW_SIZE_MAX examines the already wrapped value, so both guards pass. aligned_alloc then reserves the small wrapped size while the decoder writes scanlines sized from the original dimensions. A crafted PNG whose IHDR declares large width and h
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-56711 vlc: VLC media player: Arbitrary code execution via integer overflow in picture allocation [epel-all]
bugzilla·2026-09-09·CVSS 8.8
CVE-2026-56711 [HIGH] CVE-2026-56711 vlc: VLC media player: Arbitrary code execution via integer overflow in picture allocation [epel-all]
CVE-2026-56711 vlc: VLC media player: Arbitrary code execution via integer overflow in picture allocation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result. In AllocatePicture in src/misc/picture.c the running total is accumulated as i_bytes += p->i_pitch * p->i_lines, and both plane_t fields are declared int in include/vlc_picture.h, so the multiplication is evaluated at 32 bits and wraps before it is widened to the size_t accumulator. The overflow check that precedes it divides in 64-bit ar
Bugzilla
CVE-2026-56711 vlc: VLC media player: Arbitrary code execution via integer overflow in picture allocation
bugzilla·2026-09-09·CVSS 8.8
CVE-2026-56711 [HIGH] CVE-2026-56711 vlc: VLC media player: Arbitrary code execution via integer overflow in picture allocation
CVE-2026-56711 vlc: VLC media player: Arbitrary code execution via integer overflow in picture allocation
VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result. In AllocatePicture in src/misc/picture.c the running total is accumulated as i_bytes += p->i_pitch * p->i_lines, and both plane_t fields are declared int in include/vlc_picture.h, so the multiplication is evaluated at 32 bits and wraps before it is widened to the size_t accumulator. The overflow check that precedes it divides in 64-bit arithmetic and therefore does not constrain the product, and the subsequent comparison against PICTURE_SW_SIZE_MAX examines the already wrapped value, so both guards pass. aligned_alloc then reserves the small wrapped size while the decod
Bugzilla
CVE-2026-56711 vlc: VLC media player: Arbitrary code execution via integer overflow in picture allocation [fedora-all]
bugzilla·2026-09-09·CVSS 8.8
CVE-2026-56711 [HIGH] CVE-2026-56711 vlc: VLC media player: Arbitrary code execution via integer overflow in picture allocation [fedora-all]
CVE-2026-56711 vlc: VLC media player: Arbitrary code execution via integer overflow in picture allocation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result. In AllocatePicture in src/misc/picture.c the running total is accumulated as i_bytes += p->i_pitch * p->i_lines, and both plane_t fields are declared int in include/vlc_picture.h, so the multiplication is evaluated at 32 bits and wraps before it is widened to the size_t accumulator. The overflow check that precedes it divides in 64-bit
Hackernews
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
blogs_hackernews·2026-09-21·CVSS 10.0
CVE-2026-76460 [CRITICAL] ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.
The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not always more clarity.
Nothing here needs much drama. Just a lot of small doors left open. Here’s what happened.
## ⚡ Threat of the Week
C
2026-09-09
Published