CVE-2026-28764Disclosure(mediaarea / mediainfolib)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mediaarea mediainfolib systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A heap-based buffer overflow vulnerability exists in the LXF element parsing functionality of MediaInfoLib (version(s): 26.01). A specially crafted .lxf file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-823

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mediainfolib

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-21); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
mediainfolib

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-21: 1Mentions · 2026-05-31: 1Mentions · 2026-06-02: 1Patch / Workaround · 2026-05-31: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-31: 1Technical Details · 2026-06-02: 105-2105-3106-02
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-211
Disclosure1
2026-05-311
Patch1
2026-06-021
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 MediaArea MediaInfoLib, Heap‑Based Buffer Overflow, #CVE‑2026‑28764 (Critical) -DC-Jun2026-91 https://dailycve.com/mediaarea-mediainfolib-heap-based-buffer-overflow-cve-2026-28764-critical-dc-jun2026-91/

    Post summary

    The post announces a critical heap‑based buffer overflow in MediaArea MediaInfoLib (CVE‑2026‑28764) and links to an external article for details, but offers no PoC, exploit code, active exploitation evidence, or patch information.

    0000054
    209 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH severity CVE-2026-28764 (CVSS 7.8) Heap-based buffer overflow in MediaArea MediaInfoLib LXF element parsing. Local attack vector, no privileges required. Patch immediately if using MediaInfoLib. #CVE #Vulnerability #PatchNow https://t.co/TjDlOVkZCY

    Post summary

    A high‑severity heap‑based buffer overflow CVE‑2026‑28764 in MediaInfoLib is disclosed, and users are urged to apply the patch immediately.

    0000042
    33 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28764 MediaArea MediaInfoLib LXF element parsing heap-based buffer overflow vulnerability https://www.cve.org/CVERecord?id=CVE-2026-28764

    Post summary

    The brief statement identifies CVE‑2026‑28764 as a heap‑based buffer overflow in MediaInfoLib's LXF element parsing, but provides no further details such as PoC, exploit code, or patch information.

    00000128
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmediaareamediainfolib26.01--

Explore more