CVE-2026-21066: Input Validation
Published Aug 10, 2026
·Updated
Improper input validation in libcodec2secflacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.
Affected Software
1 affected component
libcodec2_sec_flacdec.so<SMR Aug-2026 Release 1
Event History
Aug 10, 2026
CVE Published
via MITRE·07:41 AM
Data Sourced
via MITRE·07:41 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-21066?
CVE-2026-21066 has a risk score of 35, indicating a moderate severity level.
2
How do I fix CVE-2026-21066?
To resolve CVE-2026-21066, update to the patched version included in the SMR Aug-2026 Release 1.
3
Who is affected by CVE-2026-21066?
Any system utilizing libcodec2_sec_flacdec.so prior to the August 2026 security release is potentially affected by CVE-2026-21066.
4
What type of vulnerability is CVE-2026-21066?
CVE-2026-21066 is classified as an input validation vulnerability that allows for out-of-bounds memory writes.
5
Can CVE-2026-21066 be exploited remotely?
No, CVE-2026-21066 requires local access for exploitation.