Description
FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.
Published: 2026-09-13
Score: 2.9 Low
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Monitor
AI Analysis

Impact

An insufficiently padded extradata field in the MOV parsing path of FFmpeg before version 9.0 allows an out-of-bounds read. Based on the description, it is inferred that this flaw could expose memory contents to an attacker, potentially leaking sensitive data. The vulnerability is classified as CWE‑125, an out-of-bounds read weakness.

Affected Systems

The affected product is FFmpeg, any release earlier than 9.0. This includes all FFmpeg builds prior to the 9.0 series that process MOV container files.

Risk and Exploitability

The CVSS Score is 2.9, the EPSS score is less than 1%, and the issue is not listed in the CISA KEV catalog. Exploitation requires an attacker to supply a crafted MOV container to a vulnerable FFmpeg instance; the flaw does not provide control flow hijacking or remote code execution. Consequently the overall data leakage warrants monitoring of any untrusted media input.

Generated by OpenCVE AI on September 15, 2026 at 17:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade FFmpeg to version 9.0 or later where the mov_read_iacb patch addresses extradata padding
  • If an upgrade cannot be performed immediately, configure incoming media to bypass or sanitize the extradata field, or use a validating wrapper that rejects untrusted MOV files
  • Stay alert for further updates from FFmpeg and apply patches in a timely manner

Generated by OpenCVE AI on September 15, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title ffmpeg: out-of-bounds read due to insufficiently padded extradata in the MOV parsing path
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in MOV Parsing Path of FFmpeg Before 9.0

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in MOV Parsing Path of FFmpeg Before 9.0

Sun, 13 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.
First Time appeared Ffmpeg
Ffmpeg ffmpeg
Weaknesses CWE-125
CPEs cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
Vendors & Products Ffmpeg
Ffmpeg ffmpeg
References
Metrics cvssV3_1

{'score': 2.9, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T16:03:22.113Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-52297

cve-icon Vulnrichment

Updated: 2026-09-14T16:03:19.340Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-13T22:17:00.433

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-52297

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-13T00:00:00Z

Links: CVE-2026-52297 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses