{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vlc-media-player/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-56711"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VLC media player"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","media-player"],"_cs_type":"advisory","_cs_vendors":["VideoLAN"],"content_html":"\u003cp\u003eVLC media player is affected by a heap-based buffer overflow vulnerability (CVE-2026-56711) originating in the \u003ccode\u003eAllocatePicture\u003c/code\u003e function within \u003ccode\u003esrc/misc/picture.c\u003c/code\u003e. The vulnerability occurs because the application uses 32-bit arithmetic to calculate the size of picture buffers by multiplying \u003ccode\u003ei_pitch\u003c/code\u003e and \u003ccode\u003ei_lines\u003c/code\u003e. Because these fields are declared as \u003ccode\u003eint\u003c/code\u003e, the multiplication wraps before being cast to a 64-bit accumulator. Existing overflow guards use 64-bit division, which fails to constrain the product, and subsequent validation against \u003ccode\u003ePICTURE_SW_SIZE_MAX\u003c/code\u003e checks the already wrapped value. Consequently, \u003ccode\u003ealigned_alloc\u003c/code\u003e reserves an insufficient amount of memory.\u003c/p\u003e\n\u003cp\u003eWhen the PNG decoder (\u003ccode\u003emodules/codec/png.c\u003c/code\u003e) processes a crafted file with large dimensions, it writes scanlines based on the original dimensions into the undersized buffer. This flaw is triggered simply by opening a malicious PNG file or a playlist entry containing a reference to one, without requiring non-default settings. Successful exploitation leads to arbitrary memory corruption, potentially allowing for remote code execution.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to write past the end of an allocated buffer with attacker-influenced data, leading to memory corruption. This poses a high risk to users who open media files from untrusted sources, as the attack requires no user interaction beyond opening the file. The vulnerability affects all versions of VLC media player currently using the vulnerable \u003ccode\u003eAllocatePicture\u003c/code\u003e implementation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMonitor for updates from VideoLAN and patch VLC media player to the version containing the fix for CVE-2026-56711 as soon as it is released.\u003c/li\u003e\n\u003cli\u003eImplement endpoint controls to restrict users from opening media files from untrusted network locations or unverified external drives.\u003c/li\u003e\n\u003cli\u003eUtilize application control policies to restrict the execution of VLC in high-risk, internet-facing environments if regular patching is not feasible.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T14:58:19Z","date_published":"2026-09-09T14:58:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-09-vlc-buffer-overflow/","summary":"A 32-bit integer overflow in VLC media player's picture buffer calculation allows remote attackers to trigger a heap-based buffer overflow via crafted PNG files.","title":"Heap-based Buffer Overflow in VLC Media Player via Malformed PNG","url":"https://feed.craftedsignal.io/briefs/2026-09-09-vlc-buffer-overflow/"}],"language":"en","title":"CraftedSignal Threat Feed - VLC Media Player","version":"https://jsonfeed.org/version/1.1"}