CVE-2026-2889 Details
Description
A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 0.96.6 is able to address this issue. The patch is named fd7271bae238ccb3ae8a71304ea64f0886324925. You should upgrade the affected component.
A use-after-free vulnerability has been identified in CCExtractor versions through 0.96.5. The issue arises in the 'processmp4' function within 'src/lib_ccx/mp4.c', where improper memory management leads to accessing freed memory. This vulnerability requires local access to exploit and has been publicly disclosed along with a proof-of-concept exploit.
Users are advised to upgrade to CCExtractor version 0.96.6, which addresses this vulnerability. The latest version can be downloaded from the CCExtractor GitHub releases page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 21, 2026CISA-ADP
Assessed Feb 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/CCExtractor/ccextractor/ | [email protected] | Vendor |
| https://github.com/CCExtractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925 | [email protected] | Source CodeVendor |
| https://github.com/CCExtractor/ccextractor/issues/2055 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/CCExtractor/ccextractor/pull/2057 | [email protected] | Issue TrackingVendor |
| https://github.com/CCExtractor/ccextractor/releases/tag/v0.96.6 | [email protected] | Release NotesVendor |
| https://github.com/oneafter/0123/blob/main/cc3/repro | [email protected] | Exploit |
| https://vuldb.com/?ctiid.347182 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.347182 | [email protected] | AdvisoryExploitRemedy |
| https://vuldb.com/?submit.755029 | [email protected] | Technical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-416 | Use After Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CCExtractor | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Feb 21, 2026 | New CVE Received | [email protected] |
Volerion