{"id":"CVE-2026-2889","summary":"CCExtractor mp4.c processmp4 use after free","details":"A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 0.96.6 is able to address this issue. The patch is named fd7271bae238ccb3ae8a71304ea64f0886324925. You should upgrade the affected component.","modified":"2026-08-12T15:32:14.161591Z","published":"2026-02-21T22:02:11.011Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2889.json","unresolved_ranges":[{"extracted_events":[{"introduced":"0.96.0"},{"last_affected":"0.96.0"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://github.com/CCExtractor/ccextractor/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2889.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2889"},{"type":"ADVISORY","url":"https://vuldb.com/?id.347182"},{"type":"ADVISORY","url":"https://vuldb.com/?submit.755029"},{"type":"REPORT","url":"https://github.com/CCExtractor/ccextractor/issues/2055"},{"type":"REPORT","url":"https://github.com/CCExtractor/ccextractor/pull/2057"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.347182"},{"type":"FIX","url":"https://github.com/CCExtractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925"},{"type":"FIX","url":"https://github.com/CCExtractor/ccextractor/releases/tag/v0.96.6"},{"type":"EVIDENCE","url":"https://github.com/oneafter/0123/blob/main/cc3/repro"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ccextractor/ccextractor","events":[{"introduced":"f6e9d558388d58b86ca402b068f76bbd45c0daa9"},{"fixed":"fd7271bae238ccb3ae8a71304ea64f0886324925"},{"fixed":"185631dcb0217b4ad09d43009cb69f0593996a5d"}],"database_specific":{"extracted_events":[{"introduced":"0.96.1"},{"last_affected":"0.96.1"},{"introduced":"0.96.2"},{"last_affected":"0.96.2"},{"introduced":"0.96.3"},{"last_affected":"0.96.3"},{"introduced":"0.96.4"},{"last_affected":"0.96.4"},{"introduced":"0.96.5"},{"last_affected":"0.96.5"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["0.96.1","0.96.2","0.96.3","0.96.4","0.96.5","v0.96.5","v0.96.4","v0.96.3","v0.96.2","v0.96.1"],"database_specific":{"vanir_signatures":[{"signature_type":"Line","signature_version":"v1","source":"https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925","target":{"file":"src/lib_ccx/mp4.c"},"deprecated":false,"digest":{"line_hashes":["268084206463964796024015378500305838941","254774608404346571179725158523098331095","181555103938976803185625693980704197134","13895809837220784386125091335733592582"],"threshold":0.9},"id":"CVE-2026-2889-2da52f3c"},{"deprecated":false,"digest":{"function_hash":"168783320918762457692703000749359075553","length":9778},"id":"CVE-2026-2889-3dcf91e3","signature_type":"Function","signature_version":"v1","source":"https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925","target":{"file":"src/lib_ccx/ts_tables.c","function":"parse_PMT"}},{"source":"https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925","target":{"file":"src/lib_ccx/mp4.c","function":"processmp4"},"deprecated":false,"digest":{"function_hash":"319390203887814197306087676168967181488","length":9048},"id":"CVE-2026-2889-6643399d","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925","target":{"file":"src/lib_ccx/ts_tables.c","function":"parse_PAT"},"deprecated":false,"digest":{"function_hash":"163437826467338751066847268261177864261","length":3574},"id":"CVE-2026-2889-a9c8aa4a","signature_type":"Function"},{"deprecated":false,"digest":{"line_hashes":["262233263044280559635643805212158708491","186397457794567455341493973677993329934","144833588488660765080911707542795417449","222701608767875312846042142437623115307","72091544595478024960231427334144362229","274910035117258086469502219878236509258","98069193800936354371588285816871594953","287258658584949710030799267683252424354","322249709969136488743348381363505130157","133971348316274134195358327798707233385","192690021554753830910145047033638215929","165996735762037891307360703542698719073","20631365143687003979010250023609770440","299941716532484618942222197046988800391","140964611875614036063826884500367932259","216120134842979986078832162294962308555"],"threshold":0.9},"id":"CVE-2026-2889-bb458d24","signature_type":"Line","signature_version":"v1","source":"https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925","target":{"file":"src/lib_ccx/ts_tables.c"}}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2889.json","vanir_signatures_modified":"2026-08-12T15:32:14Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P"}]}