CVE-2026-107678 | FFmpeg up to 9.0.2 MOV Demuxer encryption_info.c av_encryption_init_info_free stack-based overflow
A vulnerability has been found in FFmpeg up to 9.0.2 and classified as problematic. This affects the function av_encryption_init_info_free of the file libavutil/encryption_info.c of the component MOV Demuxer. Performing a manipulation results in stack-based buffer overflow.
This vulnerability is reported as CVE-2026-107678. The attack requires a local approach. No exploit exists.VulDB Recent EntriesRead More