Buffer Overflow Vulnerability in FFmpeg Affects Multiple Versions
CVE-2026-52295

2.9LOW

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
1 September 2026

What is CVE-2026-52295?

A buffer overflow vulnerability has been identified in FFmpeg versions 7.0 and later. This flaw exists within the libavformat component, specifically in the iamf_writer.c file. An attacker could exploit this vulnerability to create conditions causing a denial of service. By crafting a specially designed input file, an attacker may manipulate the application's behavior, potentially leading to crashes or other unintended disruptions.

Affected Version(s)

FFmpeg 0 < 9.0

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.