Description
A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
Published: 2026-07-01
Score: 6.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A null pointer dereference in the AP4_TkhdAtom::GetTrackId function of the MPC‑BE media player allows an attacker to cause a crash by providing a crafted MP4 file. The bug results in an unhandled null pointer, leading to a program crash that stops playback. Because no data is leaked or modified, the flaw is a pure availability weakness, classified as CWE‑476.

Affected Systems

The CVE applies to the MPC‑BE media player. Any build that contains the unpatched source code prior to commit 4341cb3 is affected; there is no specific version range provided beyond this pre‑commit state. No other vendors or products are listed as affected in the advisory.

Risk and Exploitability

The reported CVSS score is 6.2, indicating a medium severity denial‑of‑service vulnerability. The EPSS score is below 1 %, suggesting a very low but non‑zero likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog. An attacker can trigger the crash by delivering a malicious MP4 file, typically through local playback or remote download. Privilege escalation is not required, and the crash is confined to the media player process, but repeated crashes can degrade user experience and disrupt dependent services.

Generated by OpenCVE AI on August 1, 2026 at 23:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a build that includes commit 4341cb3 or later.
  • If updating the entire player is not feasible, apply a local patch that checks the return value of AP4_TkhdAtom::GetTrackId before use.
  • Run the media decoding component in a sandboxed environment so that a crash does not affect higher‑level applications.

Generated by OpenCVE AI on August 1, 2026 at 23:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Null Dereference in MPC-BE Media Player Leading to DoS via Malicious MP4

Wed, 29 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MP4 Track ID Parsing Leading to Denial of Service

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MP4 Track ID Parsing Leading to Denial of Service

Tue, 21 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MPC‑BE MP4 Decoder Causes DoS

Wed, 15 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MPC‑BE MP4 Decoder Causes DoS

Tue, 14 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title NULL Pointer Dereference in MPC‑BE MP4 Decoder Causes Denial of Service

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title NULL Pointer Dereference in MPC‑BE MP4 Decoder Causes Denial of Service

Mon, 13 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Null pointer dereference in MPC‑BE MP4 decoder causes DoS

Sun, 12 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Null pointer dereference in MPC‑BE MP4 decoder causes DoS

Fri, 10 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title NULL Pointer Dereference in MPC‑BE MP4 Parser Causes Denial of Service

Thu, 09 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title NULL Pointer Dereference in MPC‑BE MP4 Parser Causes Denial of Service

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MPC‑BE Media Player Enables DoS via Malicious MP4

Wed, 08 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MPC‑BE Media Player Enables DoS via Malicious MP4

Tue, 07 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference Leading to Denial of Service in MPC‑BE MP4 Parser

Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference Leading to Denial of Service in MPC‑BE MP4 Parser

Sun, 05 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

Sun, 05 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MPC‑BE MP4 Decoder Causes Crash Null Pointer Dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

Sun, 05 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MPC‑BE MP4 Decoder Causes Crash

Sat, 04 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MPC‑BE MP4 Parser Causes Denial of Service

Sat, 04 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MPC‑BE MP4 Parser Causes Denial of Service

Sat, 04 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference Causing Denial of Service in MPC‑BE MP4 Decoder

Fri, 03 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference Causing Denial of Service in MPC‑BE MP4 Decoder

Fri, 03 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MPC-BE Leading to DoS via Crafted MP4

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in MPC-BE Leading to DoS via Crafted MP4

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-476
Metrics cvssV3_1

{'score': 6.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference Leads to DoS in MPC‑BE MP4 Parsing
Weaknesses CWE-476

Thu, 02 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference Leads to DoS in MPC‑BE MP4 Parsing
Weaknesses CWE-476

Wed, 01 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-02T14:17:35.976Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36909

cve-icon Vulnrichment

Updated: 2026-07-02T14:17:33.015Z

cve-icon NVD

Status : Deferred

Published: 2026-07-01T22:16:48.113

Modified: 2026-07-02T17:42:23.640

Link: CVE-2026-36909

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T00:00:14Z

Weaknesses