
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-40962 is an integer overflow and out-of-bounds write vulnerability in FFmpeg's libavformat/mov.c, triggered via CENC (Common Encryption) subsample data when processing crafted media files. It affects all FFmpeg versions before 8.1, with affected product versions noted as 4.1 through pre-8.1 (GitHub Advisory, Red Hat Bugzilla). The vulnerability was published on April 16, 2026. CVSS scores differ by source: GitHub Advisory and ENISA assign a CVSS v3.1 score of 4.9 (Moderate) with a local attack vector, while Feedly's aggregated intelligence estimates a score of 9.8 (Critical) with a network attack vector (GitHub Advisory).
The root cause is an integer overflow (CWE-190) in FFmpeg's MOV/MP4 demuxer (libavformat/mov.c) when parsing CENC (Common Encryption) subsample data, which results in an out-of-bounds write (CWE-787). An attacker can craft a malicious media file with specially constructed CENC subsample metadata that causes an arithmetic overflow during size or index calculations, leading to a heap or stack buffer write beyond allocated bounds. The fix is tracked in FFmpeg pull request #22348 (FFmpeg PR, GitHub Advisory). A technical write-up is available at Infinit Security (Infinit Security).
Successful exploitation can result in memory corruption, potentially enabling information disclosure, data integrity violations, or denial of service. In environments where FFmpeg processes untrusted media files (e.g., media servers, transcoding pipelines, streaming platforms), an attacker could supply a crafted file to crash the FFmpeg process or potentially achieve arbitrary code execution depending on memory layout and exploit reliability. The confidentiality, integrity, and availability impacts are each rated Low under the conservative CVSS scoring, though more aggressive scoring estimates High impact across all three dimensions (GitHub Advisory, Red Hat Bugzilla).
libavformat/mov.c during size calculations.libavformat/mov.c or CENC subsample parsing.Upgrade FFmpeg to version 8.1 or later, which contains the fix for this vulnerability (FFmpeg PR, GitHub Advisory). For systems that cannot be patched immediately, restrict FFmpeg's exposure to untrusted media sources and implement input validation or sandboxing around media processing pipelines. OpenSUSE and other Linux distributions have issued security update advisories for their packaged FFmpeg versions. Monitor for exploitation attempts targeting CENC subsample data processing in media files.
Red Hat has filed a tracking bug (Bug 2458862) and assigned medium severity, with multiple product security team members listed as CC (Red Hat Bugzilla). OpenSUSE issued security announcements for affected FFmpeg packages, and the Yocto Project security mailing list has discussed the vulnerability in the context of embedded Linux builds. Mageia also published a security advisory (MGASA-2026-0153). Community discussion has been limited, with no significant social media amplification observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."