VYPR
Medium severity4.9NVD Advisory· Published Apr 16, 2026· Updated Apr 20, 2026

CVE-2026-40962

CVE-2026-40962

Description

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

Affected products

1
  • cpe:2.3:a:ffmpeg:ffmpeg:*:*:*:*:*:*:*:*
    Range: <8.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

5