CVE-2026-52295
Executive Summary
CVE-2026-52295 exposes an out‑of‑bounds read in FFmpeg versions prior to 9.0. The flaw occurs in libavformat/iamf_writer.c when extradata is copied without the required padding before GetBitContext access, potentially allowing attackers to read arbitrary memory or crash the process. The vulnerability is not yet listed in the CISA KEV database.
Authoritative CVE Metadata - CVSS Base Score: 2.9 (LOW) - Published: 2026-09-01T18:17:43.940 - Last Modified: 2026-09-13T22:16:59.693
Original Description: FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-based access in libavformat/iamf_writer.c.
"Everything is perfect in the universe � even your desire to improve it."
— Wayne Dyer
Source: NVD