Description
A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBufferSize function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
Published: 2026-07-01
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

CStreamSwitcherOutputPin::DecideBufferSize in the MPC‑BE media player performs a buffer‑size calculation that, when fed a crafted MP4 file, triggers a division‑by‑zero error. This flaw is identified as CWE‑369 and results in the application crash or a complete halt of playback, thereby denying the user any media service. The vulnerability does not expose data or execute code, but it does impact availability.

Affected Systems

Any installation of MPC‑BE built before commit 4341cb3 is affected; the vulnerable logic remains in those builds and will crash when presented with a malicious MP4 file.

Risk and Exploitability

The attack requires a malicious MP4 file to be opened or streamed by the player, so user action or a local file vector is needed. No remote code execution is possible. The CVSS score of 5.5 indicates moderate severity, and the EPSS score of less than 1% reflects a low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 1, 2026 at 23:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch provided in commit 4341cb3 or any subsequent release that fixes the division‑by‑zero error.
  • If a patch is not yet available, disable or remove MP4 playback capability from MPC‑BE to prevent the flaw from being triggered.
  • Run the media player within a sandbox or at restricted user privileges to limit the impact of a crash.
  • Scan or filter any MP4 files from untrusted sources before opening them in MPC‑BE.

Generated by OpenCVE AI on August 1, 2026 at 23:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title MP4 Buffer Size Division-by-Zero Exploit in MPC-BE Enables DoS

Wed, 29 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Division‑by‑zero in MPC‑BE Buffer Size Calculation Causes DoS

Wed, 29 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Aleksoid1978
Aleksoid1978 mpc-be
Vendors & Products Aleksoid1978
Aleksoid1978 mpc-be

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Division‑by‑zero in MPC‑BE Buffer Size Calculation Causes DoS

Wed, 22 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Vulnerability in MPC‑BE MP4 Parsing Allows DoS

Fri, 17 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Vulnerability in MPC‑BE MP4 Parsing Allows DoS

Wed, 15 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Division‑By‑Zero Vulnerability in MPC‑BE Buffer‑Size Calculation Enables Denial of Service

Tue, 14 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Division‑By‑Zero Vulnerability in MPC‑BE Buffer‑Size Calculation Enables Denial of Service

Mon, 13 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Denial of Service via Division-by-Zero in MPC‑BE MP4 Parsing

Sat, 11 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Denial of Service via Division-by-Zero in MPC‑BE MP4 Parsing

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Division‑by‑Zero in MPC‑BE MP4 Buffer Size Calculation Causes DoS

Wed, 08 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Division‑by‑Zero in MPC‑BE MP4 Buffer Size Calculation Causes DoS

Tue, 07 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Vulnerability in MPC-BE Buffer-Size Calculation Enables Denial of Service

Mon, 06 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Vulnerability in MPC-BE Buffer-Size Calculation Enables Denial of Service

Mon, 06 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Buffer Size Bug Causes DoS in MPC-BE

Sun, 05 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Buffer Size Bug Causes DoS in MPC-BE

Sun, 05 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Crash in Media Player Classic – Basic Edition Leads to DoS via Malicious MP4

Sat, 04 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Crash in Media Player Classic – Basic Edition Leads to DoS via Malicious MP4

Sat, 04 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Division‑by‑Zero in MPC‑BE Buffer Size Calculation Causes Denial of Service

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Division‑by‑Zero in MPC‑BE Buffer Size Calculation Causes Denial of Service

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Crash in MPC-BE MP4 Parsing Leads to DoS

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Division-by-Zero Crash in MPC-BE MP4 Parsing Leads to DoS

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-369
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 02 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Division‑By‑Zero Vulnerability in MPC‑BE Causing DoS via Malicious MP4
Weaknesses CWE-369

Thu, 02 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Division‑By‑Zero Vulnerability in MPC‑BE Causing DoS via Malicious MP4
Weaknesses CWE-369

Wed, 01 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description A division-by-zero vulnerability in the CStreamSwitcherOutputPin::DecideBufferSize function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
References

Subscriptions

Aleksoid1978 Mpc-be
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-02T14:40:28.915Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-36911

cve-icon Vulnrichment

Updated: 2026-07-02T14:39:58.973Z

cve-icon NVD

Status : Deferred

Published: 2026-07-01T22:16:48.703

Modified: 2026-07-02T17:42:23.640

Link: CVE-2026-36911

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T00:00:14Z

Weaknesses