Memcpy-param-overlap in zxc_decompress_chunk_wrapper_default
A vulnerability was identified in the zxc library related to a memcpy parameter overlap in the function zxc_decompress_chunk_wrapper_default, as reported by OSS-Fuzz. This issue causes a crash during decompression operations. A patch is available to address this flaw.
AI Analysis
Technical Summary
The vulnerability involves a memcpy parameter overlap detected in the zxc_decompress_chunk_wrapper_default function within the zxc library. This flaw was discovered through OSS-Fuzz testing and results in a crash state during decompression, specifically in the zxc_decompress_frame and fuzz_decompress.c components. The issue is classified as a memory operation error due to overlapping parameters in memcpy, which can lead to undefined behavior or program crashes. A patch has been made available to fix this defect.
Potential Impact
The impact of this vulnerability is a crash during decompression operations in the zxc library, which could potentially lead to denial of service or instability in applications relying on this library. There is no indication of known exploits in the wild or further impact such as code execution from the provided data.
Mitigation Recommendations
A patch is available for this vulnerability. Users of the zxc library should apply the official fix to prevent crashes caused by memcpy parameter overlap in the decompression function. No additional mitigation steps are indicated by the vendor or OSS-Fuzz report.
Memcpy-param-overlap in zxc_decompress_chunk_wrapper_default
Description
A vulnerability was identified in the zxc library related to a memcpy parameter overlap in the function zxc_decompress_chunk_wrapper_default, as reported by OSS-Fuzz. This issue causes a crash during decompression operations. A patch is available to address this flaw.
Affected software
pkg:generic/zxcRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability involves a memcpy parameter overlap detected in the zxc_decompress_chunk_wrapper_default function within the zxc library. This flaw was discovered through OSS-Fuzz testing and results in a crash state during decompression, specifically in the zxc_decompress_frame and fuzz_decompress.c components. The issue is classified as a memory operation error due to overlapping parameters in memcpy, which can lead to undefined behavior or program crashes. A patch has been made available to fix this defect.
Potential Impact
The impact of this vulnerability is a crash during decompression operations in the zxc library, which could potentially lead to denial of service or instability in applications relying on this library. There is no indication of known exploits in the wild or further impact such as code execution from the provided data.
Mitigation Recommendations
A patch is available for this vulnerability. Users of the zxc library should apply the official fix to prevent crashes caused by memcpy parameter overlap in the decompression function. No additional mitigation steps are indicated by the vendor or OSS-Fuzz report.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- OSV-2026-1157
- Osv Schema Version
- 1.8.0
- Aliases
- []
- Ecosystems
- ["OSS-Fuzz"]
- Database Specific Severity
- null
- Cvss Version
- null
Threat ID: 6a81d708bf8831d5394a16b7
Added to database: 08/16/2026, 15:28:08 UTC
Last enriched: 08/16/2026, 15:32:23 UTC
Last updated: 08/16/2026, 16:41:24 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.