Out-of-Bounds Read Vulnerability in FFmpeg Media Processing Library
CVE-2026-52297

2.9LOW

Key Information:

Vendor

Ffmpeg

Status
Vendor
CVE Published:
13 September 2026

What is CVE-2026-52297?

An out-of-bounds read vulnerability exists in FFmpeg due to insufficient padding of extradata when parsing MOV files. This issue arises in the mov_read_iacb function within libavformat/mov.c. Attackers could exploit this vulnerability to access unauthorized memory regions, potentially leading to information disclosure or application crashes when processing specially crafted MOV files. It is essential for users of FFmpeg to ensure their systems are updated to version 9.0 or later to mitigate this risk.

Affected Version(s)

FFmpeg 0 < 9.0

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.