Back

MEDIUM

ffmpeg: out-of-bounds read due to insufficiently padded extradata in the MOV parsing path

Published Sep 13, 2026

Description

FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.

Affected products

Remediation

Red Hat statement

To exploit this issue, an attacker needs to convince a user to parse a specially crafted MOV file, limiting its exposure. Furthermore, this issue can cause an application crash with no other security impact. For these reasons, this vulnerability has been rated with a moderate severity.

Red Hat mitigation

Do not parse untrusted files with the MOV demuxer in FFmpeg.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 13, 2026
Updated Sep 14, 2026
Reserved Jun 8, 2026
CISA Vulnrichment
Updated Sep 14, 2026
NVD
Status Received
Modified Sep 14, 2026
Red Hat
Severity Moderate
Public date Sep 13, 2026