GHSA-vp63-fqg3-cph4LowCVSS 2.9
FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in...
🔗 CVE IDs covered (1)
📋 Description
FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.
🔗 References (5)
- https://nvd.nist.gov/vuln/detail/CVE-2026-52297
- https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22988
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/8439e0203744a30d280668fcd086f74ed5001da1
- https://github.com/Kenan-Kamel/VulnerabilitiesReference/tree/main/FFmpeg/ExtradataPadding
- https://github.com/advisories/GHSA-vp63-fqg3-cph4