MEDIUMUnknown →
FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.
FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.
Affected packages
- ffmpeg
- libav
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://www.cve.org/CVERecord?id=CVE-2026-52297
- https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/22988
- https://git.ffmpeg.org/gitweb/ffmpeg.git/commit/8439e0203744a30d280668fcd086f74ed5001da1
- https://github.com/Kenan-Kamel/VulnerabilitiesReference/tree/main/FFmpeg/ExtradataPadding
Structured record: https://ubuntu.com/security/CVE-2026-52297
Recommended response stack
Snyk — Scan your dependencies in CI and fix this vulnerability.→Socket — Detect malicious and compromised packages before they ship.→
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta