CVE-2026-36909 Details
Description
A NULL pointer dereference in the AP4_TkhdAtom::GetTrackId() function of Aleksoid1978 MPC-BE before commit 4341cb3 allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
A NULL pointer dereference vulnerability has been identified in Aleksoid1978 MPC-BE, prior to the commit 4341cb3. This vulnerability occurs in the AP4_TkhdAtom::GetTrackId() function, where improper handling of crafted MP4 files can lead to a denial-of-service condition by causing the application to crash.
Users can update to MPC-BE version 1.8.9.61 or later, which includes the necessary fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 1, 2026CISA-ADP
Assessed Jul 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/Aleksoid1978/MPC-BE/issues/1062 | [email protected] | BundleExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/axiomatic-systems/Bento4/issues/965 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Aleksoid1978 MPC-BE | < 4341cb3 |
CPE
Remediation
| |
| Axiomatic Systems Bento4 | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 2, 2026 | CVE Modified | CISA-ADP |
| Jul 1, 2026 | New CVE Received | [email protected] |
Volerion