Executive brief
A vulnerability exists in GPAC's MP4Box, a popular tool for processing multimedia files. By tricking a user into opening a specially crafted video file (MPEG-2 TS), an attacker can cause the application to crash. This results in a denial of service, potentially disrupting media processing workflows or automated video conversion services.
Technical details
A use-after-free vulnerability exists in the gf_sei_load_from_state_internal function within filters/sei_load.c of GPAC. The issue occurs when processing crafted MPEG-2 TS files containing HEVC/VVC streams. Under specific conditions, the NALU demuxer frees a heap buffer that is subsequently accessed by the SEI loading logic. An attacker can exploit this by providing a malicious media file to be processed by MP4Box, leading to an application crash (Denial of Service). The vulnerability was addressed in version 26.02.0.
Affected products
- GPAC Project GPAC / MP4Box before 26.02.0
Timeline
- 2026-06-25: disclosed
- 2026-06-25: advisory
References
- https://github.com/gpac/gpac/commit/8f404bd581e455267482f86272169a742f654b97
- https://github.com/gpac/gpac/issues/3278
- https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/32/32_filters_sei_load_c_225_in_gf_sei_load_from_state_internal
- https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/32/README.md
- https://infosec.exchange/@sigdevel/116778370895014131