Out-of-bounds Read Vulnerability in FFmpeg Affected by Missing Padding
CVE-2026-52296

2.9LOW

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
13 September 2026

What is CVE-2026-52296?

An out-of-bounds read vulnerability exists in FFmpeg due to missing required padding during the allocation of WMA extradata within the libavcodec module. This flaw can potentially allow attackers to read memory locations beyond the intended bounds, leading to information disclosure or unwanted behavior in applications using the affected versions.

Affected Version(s)

FFmpeg 0 < 9.0

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.