
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-52296 is a low-severity out-of-bounds read vulnerability in FFmpeg's WMA encoder component (libavcodec/wmaenc.c), caused by missing required padding in WMA extradata allocation paths. It affects all FFmpeg versions from 2.4 up to (but not including) 9.0, and was publicly disclosed on September 13, 2026. The vulnerability was discovered and reported by Kenan Alghythee (University of Illinois Chicago) and colleagues, with upstream fixes merged via FFmpeg PR #22988. It carries a CVSS v3.1 base score of 2.9 (Low) (GitHub Advisory, Researcher Reference).
The root cause is classified as CWE-125 (Out-of-bounds Read): the WMA encoder in libavcodec/wmaenc.c allocates extradata buffers without the required padding needed for subsequent bitreader access, allowing reads beyond the intended buffer boundary. The flaw was introduced by commit d2a4e4b9cc9a0c2661e1c1d6f6b51babac2cec1b in 2014 and persisted until the fix was committed. Exploitation requires local access and high attack complexity — an attacker must supply a specially crafted WMA audio file for FFmpeg to process. The fix was applied in commit 23227a444de4a8f7696f46660cdd044b460f7e47 and merged via PR #22988 (Researcher Reference, GitHub Advisory).
Successful exploitation results in a heap out-of-bounds read, which can cause the FFmpeg process to crash, resulting in a denial-of-service condition. There is no impact on confidentiality or data integrity — the vulnerability does not enable code execution, privilege escalation, or data exfiltration. The scope is limited to the FFmpeg process itself, with no evidence of lateral movement potential (GitHub Advisory, Researcher Reference).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The EPSS score is 0.0, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and high attack complexity, significantly limiting the practical attack surface (GitHub Advisory).
libavcodec/wmaenc.c during extradata allocation.ffmpeg -i malicious.wma output.wav), causing the WMA encoder to allocate an extradata buffer without required padding.libavcodec/wmaenc.c or heap-buffer-overflow on read in WMA extradata allocation paths.Upgrade FFmpeg to version 9.0 or later, which includes the fix merged via PR #22988 (commit 23227a444de4a8f7696f46660cdd044b460f7e47). As an interim measure, restrict local access to systems running vulnerable FFmpeg versions and avoid processing untrusted or unknown WMA audio files. No configuration-based workaround is available that fully mitigates the vulnerability without upgrading (GitHub Advisory, Researcher Reference).
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
ffmpeg
devel
ffmpeg
focal (esm-apps)
ffmpeg
jammy
ffmpeg
jammy (esm-apps)
ffmpeg
noble
ffmpeg
noble (esm-apps)
ffmpeg
resolute
ffmpeg
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."