A vulnerability was detected in CCExtractor up to 0.96.5. Affected is the function processmp4 in the library src/lib_ccx/mp4.c. Performing a manipulation results in use after free. The attack is only possible with local access. The exploit is now public and may be used. Upgrading to version 0.96.6 is able to address this issue. The patch is named fd7271bae238ccb3ae8a71304ea64f0886324925. You should upgrade the affected component.
{
"cna_assigner": "VulDB",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/2xxx/CVE-2026-2889.json",
"unresolved_ranges": [
{
"extracted_events": [
{
"introduced": "0.96.0"
},
{
"last_affected": "0.96.0"
}
],
"source": "AFFECTED_FIELD"
}
],
"cwe_ids": [
"CWE-119",
"CWE-416"
]
}{
"extracted_events": [
{
"introduced": "0.96.1"
},
{
"last_affected": "0.96.1"
},
{
"introduced": "0.96.2"
},
{
"last_affected": "0.96.2"
},
{
"introduced": "0.96.3"
},
{
"last_affected": "0.96.3"
},
{
"introduced": "0.96.4"
},
{
"last_affected": "0.96.4"
},
{
"introduced": "0.96.5"
},
{
"last_affected": "0.96.5"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}[
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"268084206463964796024015378500305838941",
"254774608404346571179725158523098331095",
"181555103938976803185625693980704197134",
"13895809837220784386125091335733592582"
]
},
"id": "CVE-2026-2889-2da52f3c",
"signature_type": "Line",
"source": "https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925",
"target": {
"file": "src/lib_ccx/mp4.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 9778.0,
"function_hash": "168783320918762457692703000749359075553"
},
"id": "CVE-2026-2889-3dcf91e3",
"signature_type": "Function",
"source": "https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925",
"target": {
"function": "parse_PMT",
"file": "src/lib_ccx/ts_tables.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 9048.0,
"function_hash": "319390203887814197306087676168967181488"
},
"id": "CVE-2026-2889-6643399d",
"signature_type": "Function",
"source": "https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925",
"target": {
"function": "processmp4",
"file": "src/lib_ccx/mp4.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"length": 3574.0,
"function_hash": "163437826467338751066847268261177864261"
},
"id": "CVE-2026-2889-a9c8aa4a",
"signature_type": "Function",
"source": "https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925",
"target": {
"function": "parse_PAT",
"file": "src/lib_ccx/ts_tables.c"
}
},
{
"signature_version": "v1",
"deprecated": false,
"digest": {
"threshold": 0.9,
"line_hashes": [
"262233263044280559635643805212158708491",
"186397457794567455341493973677993329934",
"144833588488660765080911707542795417449",
"222701608767875312846042142437623115307",
"72091544595478024960231427334144362229",
"274910035117258086469502219878236509258",
"98069193800936354371588285816871594953",
"287258658584949710030799267683252424354",
"322249709969136488743348381363505130157",
"133971348316274134195358327798707233385",
"192690021554753830910145047033638215929",
"165996735762037891307360703542698719073",
"20631365143687003979010250023609770440",
"299941716532484618942222197046988800391",
"140964611875614036063826884500367932259",
"216120134842979986078832162294962308555"
]
},
"id": "CVE-2026-2889-bb458d24",
"signature_type": "Line",
"source": "https://github.com/ccextractor/ccextractor/commit/fd7271bae238ccb3ae8a71304ea64f0886324925",
"target": {
"file": "src/lib_ccx/ts_tables.c"
}
}
]
"2026-08-07T21:53:35Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-2889.json"