{"id":"CVE-2026-2245","summary":"CCExtractor MPEG-TS File ts_tables.c parse_PMT out-of-bounds","details":"A vulnerability was identified in CCExtractor up to 183. This affects the function parse_PAT/parse_PMT in the library src/lib_ccx/ts_tables.c of the component MPEG-TS File Parser. Such manipulation leads to out-of-bounds read. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The name of the patch is fd7271bae238ccb3ae8a71304ea64f0886324925. It is best practice to apply a patch to resolve this issue.","modified":"2026-08-12T15:32:50.963411Z","published":"2026-02-09T19:02:10.417Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2245.json","unresolved_ranges":[{"extracted_events":[{"introduced":"183"},{"last_affected":"183"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/CCExtractor/ccextractor/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2245.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2245"},{"type":"ADVISORY","url":"https://vuldb.com/?id.344991"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.753159"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.753160"},{"type":"REPORT","url":"https://github.com/CCExtractor/ccextractor/issues/2053"},{"type":"REPORT","url":"https://github.com/CCExtractor/ccextractor/pull/2057"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.344991"},{"type":"FIX","url":"https://github.com/CCExtractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925"},{"type":"EVIDENCE","url":"https://github.com/oneafter/0123/blob/main/cc1/repro"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ccextractor/ccextractor","events":[{"introduced":"0"},{"fixed":"fd7271bae238ccb3ae8a71304ea64f0886324925"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v0.96.5","v0.96.4","v0.96.3","v0.96.2","v0.96.1","v0.96","v0.89","v0.94","v0.93","v0.92","v0.91","v0.90","v0.88","v0.87","v0.86","v0.85b","v0.85","v0.84","v0.83","v0.79","v0.78","v0.77","v0.76","v0.75","v0.74","v0.73","v0.70"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2245.json","vanir_signatures_modified":"2026-08-12T15:32:50Z","vanir_signatures":[{"deprecated":false,"digest":{"line_hashes":["268084206463964796024015378500305838941","254774608404346571179725158523098331095","181555103938976803185625693980704197134","13895809837220784386125091335733592582"],"threshold":0.9},"id":"CVE-2026-2245-2da52f3c","signature_type":"Line","signature_version":"v1","source":"https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925","target":{"file":"src/lib_ccx/mp4.c"}},{"target":{"function":"parse_PMT","file":"src/lib_ccx/ts_tables.c"},"deprecated":false,"digest":{"length":9778,"function_hash":"168783320918762457692703000749359075553"},"id":"CVE-2026-2245-3dcf91e3","signature_type":"Function","signature_version":"v1","source":"https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925","target":{"file":"src/lib_ccx/mp4.c","function":"processmp4"},"deprecated":false,"digest":{"function_hash":"319390203887814197306087676168967181488","length":9048},"id":"CVE-2026-2245-6643399d"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925","target":{"file":"src/lib_ccx/ts_tables.c","function":"parse_PAT"},"deprecated":false,"digest":{"function_hash":"163437826467338751066847268261177864261","length":3574},"id":"CVE-2026-2245-a9c8aa4a"},{"deprecated":false,"digest":{"line_hashes":["262233263044280559635643805212158708491","186397457794567455341493973677993329934","144833588488660765080911707542795417449","222701608767875312846042142437623115307","72091544595478024960231427334144362229","274910035117258086469502219878236509258","98069193800936354371588285816871594953","287258658584949710030799267683252424354","322249709969136488743348381363505130157","133971348316274134195358327798707233385","192690021554753830910145047033638215929","165996735762037891307360703542698719073","20631365143687003979010250023609770440","299941716532484618942222197046988800391","140964611875614036063826884500367932259","216120134842979986078832162294962308555"],"threshold":0.9},"id":"CVE-2026-2245-bb458d24","signature_type":"Line","signature_version":"v1","source":"https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925","target":{"file":"src/lib_ccx/ts_tables.c"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}