CVE-2026-88377: n/a
Bento4 version 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. This flaw occurs when processing a specially crafted MP4 file with an atom size smaller than the expected header size, leading to an underflow in payload size calculation. The vulnerability can cause invalid or NULL pointers to be used during buffer operations, resulting in application crashes and denial of service.
AI Analysis
Technical Summary
CVE-2026-88377 describes an integer underflow vulnerability in Bento4 1.6.0.0's avcC and hvcC atom parsers. When an MP4 file contains an atom with a declared size smaller than AP4_ATOM_HEADER_SIZE, the functions AP4_AvccAtom::Create() or AP4_HvccAtom::Create() miscalculate the payload size due to underflow. This leads to oversized buffer operations that pass invalid or NULL pointers to the AP4_DataBuffer copy path, causing application termination and denial of service.
Potential Impact
The vulnerability can cause affected applications using Bento4 1.6.0.0 to crash or terminate unexpectedly when processing maliciously crafted MP4 files. This results in a denial of service condition. There is no information about code execution or data corruption beyond application termination.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid processing untrusted MP4 files with Bento4 1.6.0.0 to mitigate risk.
CVE-2026-88377: n/a
Description
Bento4 version 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. This flaw occurs when processing a specially crafted MP4 file with an atom size smaller than the expected header size, leading to an underflow in payload size calculation. The vulnerability can cause invalid or NULL pointers to be used during buffer operations, resulting in application crashes and denial of service.
Affected software
pkg:github/axiomatic-systems/Bento4Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-88377 describes an integer underflow vulnerability in Bento4 1.6.0.0's avcC and hvcC atom parsers. When an MP4 file contains an atom with a declared size smaller than AP4_ATOM_HEADER_SIZE, the functions AP4_AvccAtom::Create() or AP4_HvccAtom::Create() miscalculate the payload size due to underflow. This leads to oversized buffer operations that pass invalid or NULL pointers to the AP4_DataBuffer copy path, causing application termination and denial of service.
Potential Impact
The vulnerability can cause affected applications using Bento4 1.6.0.0 to crash or terminate unexpectedly when processing maliciously crafted MP4 files. This results in a denial of service condition. There is no information about code execution or data corruption beyond application termination.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid processing untrusted MP4 files with Bento4 1.6.0.0 to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-09-10T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 6ab5545df7a7c5410690de3f
Added to database: 09/24/2026, 16:48:29 UTC
Last enriched: 09/24/2026, 17:03:35 UTC
Last updated: 09/24/2026, 17:07:44 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.