Back

HIGH

A heap-based buffer overflow vulnerability exists in the ID3v2 parsing functionality of MediaInfoLib (version(s): 26.01)

Published May 26, 2026

Description

A heap-based buffer overflow vulnerability exists in the ID3v2 parsing functionality of MediaInfoLib (version(s): 26.01). A specially crafted media file that contains ID3v2 tags can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner talos
Published May 26, 2026
Updated Sep 23, 2026
Reserved Feb 12, 2026
CISA Vulnrichment
Updated May 26, 2026
NVD
Status Modified
Modified Sep 23, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner talos
Published May 26, 2026
Updated Sep 23, 2026
Exploited since n/a
EUVD-2026-31807