EIP-2026-100042

PRE-CVE

LG MRA58K - Out-of-Bounds Heap Read in CAVIFileParser::Destroy Resulting in Invalid Free

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-100042. PoCs published by Google Security Research.

AI-analyzed exploit summary This exploit targets a vulnerability in the CAVIFileParser object in LG's AVI parser library, where an out-of-bounds free occurs due to improper validation of the number of streams in an AVI file. The PoC triggers a crash by freeing an invalid pointer outside the bounds of the CAVIFileParser object.

Description

LG MRA58K - Out-of-Bounds Heap Read in CAVIFileParser::Destroy Resulting in Invalid Free

Exploits (1)

exploitdb WORKING POC VERIFIED
by Google Security Research · textdosandroid
https://www.exploit-db.com/exploits/42169

This exploit targets a vulnerability in the CAVIFileParser object in LG's AVI parser library, where an out-of-bounds free occurs due to improper validation of the number of streams in an AVI file. The PoC triggers a crash by freeing an invalid pointer outside the bounds of the CAVIFileParser object.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: LG AVI Parser (liblg_parser_avi.so) on Android 6.0
No auth needed
Prerequisites: A maliciously crafted AVI file with more than 40 streams and truncated strl LIST objects
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026