Out-of-Bounds Read Vulnerability in FFmpeg Media Processing Library
CVE-2026-52297
2.9LOW
What is CVE-2026-52297?
An out-of-bounds read vulnerability exists in FFmpeg due to insufficient padding of extradata when parsing MOV files. This issue arises in the mov_read_iacb function within libavformat/mov.c. Attackers could exploit this vulnerability to access unauthorized memory regions, potentially leading to information disclosure or application crashes when processing specially crafted MOV files. It is essential for users of FFmpeg to ensure their systems are updated to version 9.0 or later to mitigate this risk.
Affected Version(s)
FFmpeg 0 < 9.0
