CVE-2026-24073: Out-of-bounds Write in Video
Published Sep 17, 2026
·Updated
Memory corruption when processing decode statistics due to insufficient validation of offset against structure size.
Event History
Sep 17, 2026
CVE Published
via MITRE·04:11 AM
Data Sourced
via MITRE·04:11 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require network access or user interaction?
The vector is local (AV:L), so the attacker needs local access. No user interaction is required (UI:N).
2
What level of access does an attacker need, and what is the potential impact?
The attacker needs low privileges (PR:L). Successful exploitation can have high impact on confidentiality, integrity, and availability, while the security scope remains unchanged (S:U).