CVE-2026-88377 Details
Description
Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially crafted MP4 file containing an atom with a declared size smaller than AP4_ATOM_HEADER_SIZE can cause AP4_AvccAtom::Create() or AP4_HvccAtom::Create() to underflow the payload-size calculation. The resulting oversized buffer operation can cause invalid or NULL pointers to be passed to the AP4_DataBuffer copy path, resulting in application termination and denial of service.
An integer underflow vulnerability has been identified in Bento4 version 1.6.0.0, specifically within the avcC and hvcC configuration atom parsers. The vulnerability arises when an MP4 file contains an atom with a declared size smaller than the minimum required for a valid atom header. This discrepancy allows the atom parser to incorrectly calculate the payload size, leading to an underflow. The resulting oversized buffer operation can cause invalid or null pointers to be passed to the AP4_DataBuffer copy function, ultimately causing the application to crash and creating a denial-of-service condition.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 24, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/axiomatic-systems/Bento4/issues/1092 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Bento4 | 1.6.0.0 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 24, 2026 | New CVE Received | [email protected] |
Volerion