Heap-based buffer overflow in ZoneMinder - #VU153357
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to corrupt heap memory.
The vulnerability exists due to a heap-based buffer overflow in Image::ReadJpeg() when decoding a JPEG with dimensions larger than the configured monitor image. A local user can replace the monitored file with a specially crafted JPEG to corrupt heap memory.
Exploitation requires a File source-type monitor, which is not the default configuration, and write access to its source file. No ZoneMinder authentication is required.