Description
FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.
Published: 2026-09-13
Score: 2.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Data Disclosure
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a missing required padding in the WMA extradata allocation code path of FFmpeg prior to version 9.0, leading to an out‑of‑bounds read. This flaw enables an attacker to read data beyond the allocated buffer, potentially exposing confidential information from memory. The weakness is classified as CWE‑125: Out‑of‑Bounds Read.

Affected Systems

FFmpeg, all releases before 9.0 that use the WMA codec. The flaw resides in libavcodec/wmaenc.c and affects any system that decodes or encodes WMA media streams with FFmpeg.

Risk and Exploitability

The CVSS base score is 2.9, indicating low severity. The EPSS score is less than 1%, reflecting an extremely low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting a limited attack window. Exploitation likely requires a crafted WMA file or code execution within a media processing environment, meaning the attack vector is either local or requires the target to process malicious media.

Generated by OpenCVE AI on September 15, 2026 at 17:44 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FFmpeg to version 9.0 or later, which includes the missing padding fix.
  • If upgrade is not immediately possible, apply the patch from the FFmpeg pull request (commit 23227a444de4a8f7696f46660cdd044b460f7e47) to the source code and rebuild the library.
  • Restrict or sanitize any user‑supplied WMA media inputs, or disable the WMA codec if not needed, until a patch is installed.

Generated by OpenCVE AI on September 15, 2026 at 17:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title ffmpeg: out-of-bounds read due to missing required padding in WMA extradata allocation paths
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in FFmpeg WMA Extradata Allocation

Mon, 14 Sep 2026 01:15:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Read in FFmpeg WMA Extradata Allocation

Sun, 13 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.
First Time appeared Ffmpeg
Ffmpeg ffmpeg
Weaknesses CWE-125
CPEs cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Vendors & Products Ffmpeg
Ffmpeg ffmpeg
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-15T17:15:08.538Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52296

cve-icon Vulnrichment

Updated: 2026-09-15T17:15:04.584Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-13T22:17:00.297

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-52296

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-13T00:00:00Z

Links: CVE-2026-52296 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses