CVE-2026-96611
6.9 MEDIUMPublished 2026-09-23 · Updated 2026-09-26
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values from a crafted HEIF ispe box are stored into signed int fields without bounds checking, allowing values exceeding INT_MAX to become negative. In read_image_grid(), accumulating these values causes signed integer overflow (undefined behavior per C17 section 6.5), which on x86 wraps to a small positive value, bypassing downstream validity checks.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L
Weaknesses
CWE-190
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- MEDIUMCVE-2025-14181PoC
- HIGHCVE-2026-100208
- MEDIUMCVE-2026-101279
- LOWCVE-2026-102620PoC
- LOWCVE-2026-102621PoC
- MEDIUMCVE-2026-102633PoC
- MEDIUMCVE-2026-102804PoC
- MEDIUMCVE-2026-102805PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.