Description
VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.
Published: 2026-09-09
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a memory‑safety flaw that can be triggered by processing crafted media files. Based on the description, it is inferred that the attack vector requires the user to open a malicious media file, meaning exploitation requires user interaction. The flaw allows the attacker to either cause the VLC process to terminate or execute code with the privileges of that process.

Affected Systems

All versions of VideoLAN VLC media player from 3.0.0 up to and including 3.0.23 are affected. No sub‑version specific patches are listed; the vulnerability resides in the core picture allocation routines shared across these releases.

Risk and Exploitability

The CVSS score of 7.3 indicates a moderate‑to‑high severity vulnerability. EPSS data remains low, at < 1%, suggesting a very low likelihood of widespread exploitation in the near term. The flaw is not catalogued in the CISA KEV list. The attack requires a malicious media file to be opened by the user; the attack vector is therefore user‑directed, and exploitation is classified as user‑initiated. If exploited, the attacker may cause the VLC process to terminate or execute code with the process's privileges, potentially compromising the host system.

Generated by OpenCVE AI on September 21, 2026 at 05:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update VLC media player to a version that fixes the integer overflow in picture allocation.
  • Until the update can be applied, avoid opening unknown PNG files or playlists that may contain large dimensions.
  • Configure your environment or VLC policy settings to reject or quarantine PNG files with dimensions exceeding safe thresholds.

Generated by OpenCVE AI on September 21, 2026 at 05:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6515-1 vlc security update
History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
Description VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result. In AllocatePicture in src/misc/picture.c the running total is accumulated as i_bytes += p->i_pitch * p->i_lines, and both plane_t fields are declared int in include/vlc_picture.h, so the multiplication is evaluated at 32 bits and wraps before it is widened to the size_t accumulator. The overflow check that precedes it divides in 64-bit arithmetic and therefore does not constrain the product, and the subsequent comparison against PICTURE_SW_SIZE_MAX examines the already wrapped value, so both guards pass. aligned_alloc then reserves the small wrapped size while the decoder writes scanlines sized from the original dimensions. A crafted PNG whose IHDR declares large width and height reaches this path through the image demuxer, whose only size guard is on the input file's byte count rather than the declared dimensions, and the decoder in modules/codec/png.c writes past the end of the allocation with attacker-influenced length and content. Opening the file directly or through a playlist entry is sufficient, with no non-default settings. VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.
Title VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Write via Integer Overflow in Picture Allocation VLC media player 3.0.0 through 3.0.23 memory corruption vulnerability
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Thu, 10 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description VLC media player computes the size of a picture buffer with 32-bit arithmetic and allocates from the wrapped result. In AllocatePicture in src/misc/picture.c the running total is accumulated as i_bytes += p->i_pitch * p->i_lines, and both plane_t fields are declared int in include/vlc_picture.h, so the multiplication is evaluated at 32 bits and wraps before it is widened to the size_t accumulator. The overflow check that precedes it divides in 64-bit arithmetic and therefore does not constrain the product, and the subsequent comparison against PICTURE_SW_SIZE_MAX examines the already wrapped value, so both guards pass. aligned_alloc then reserves the small wrapped size while the decoder writes scanlines sized from the original dimensions. A crafted PNG whose IHDR declares large width and height reaches this path through the image demuxer, whose only size guard is on the input file's byte count rather than the declared dimensions, and the decoder in modules/codec/png.c writes past the end of the allocation with attacker-influenced length and content. Opening the file directly or through a playlist entry is sufficient, with no non-default settings.
Title VLC media player 3.0.0 through 3.0.23 Heap Out-of-Bounds Write via Integer Overflow in Picture Allocation
First Time appeared Videolan
Videolan vlc Media Player
Weaknesses CWE-190
CWE-787
CPEs cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:*
Vendors & Products Videolan
Videolan vlc Media Player
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Videolan Vlc Media Player
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T17:23:09.134Z

Reserved: 2026-06-22T18:48:27.060Z

Link: CVE-2026-56711

cve-icon Vulnrichment

Updated: 2026-09-18T17:17:45.878Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T14:17:12.717

Modified: 2026-09-18T18:17:07.347

Link: CVE-2026-56711

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-09T13:31:58Z

Links: CVE-2026-56711 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:45:10Z

Weaknesses