CVE-2026-36908 Details
Description
A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
A stack overflow vulnerability has been identified in Axiomatic Systems Bento4 versions prior to 1.8.9. The issue arises in the AP4_Array component, specifically within the AP4_TrunAtom::Entry::EnsureCapacity function. This vulnerability allows attackers to cause a denial-of-service (DoS) by exploiting a crafted MP4 file.
Users can update to Bento4 version 1.8.9 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 26, 2026CISA-ADP
Assessed Jun 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Aleksoid1978/MPC-BE/issues/1005 | CISA-ADP | ExploitIssue TrackingTechnical Description |
| https://github.com/z1r00/fuzz_vuln/blob/main/Bento4/mp42aac/poc4.zip | CISA-ADP | |
| https://github.com/Aleksoid1978/MPC-BE/issues/1005 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://github.com/axiomatic-systems/Bento4/issues/842 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Axiomatic Systems Bento4 | < 1.8.9 (semver) |
CPE
Remediation
| |
| Aleksoid1978 MPC-BE | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 29, 2026 | CVE Modified | CISA-ADP |
| Jun 26, 2026 | New CVE Received | [email protected] |
Volerion