Executive brief
A vulnerability exists in GPAC's MP4Box, a popular tool for processing multimedia files. By tricking a user into opening a specially crafted media file, an attacker can cause the application to crash. This results in a denial of service, potentially disrupting media processing workflows or automated systems that rely on this software.
Technical details
A heap-based buffer overflow exists in GPAC Project/MP4Box within the gf_media_import function in media_tools/media_import.c (previously av_parsers.c). The vulnerability is caused by unsafe access to a heap buffer when processing the language property of a media stream; specifically, the code attempts to read multiple bytes from a string without verifying that the string length is at least 3 bytes. An attacker can exploit this by providing a crafted media file with a short or empty language string, leading to an out-of-bounds read and application crash (Denial of Service). The issue has been addressed in version 26.02.0 and via a specific commit to the GPAC repository.
Affected products
- GPAC Project GPAC / MP4Box before 26.02.0
Timeline
- 2026-06-24: disclosed: NVD publication date
- 2026-06-24: advisory
- 2025-02-26: patched: Based on version numbering 26.02.0 and commit history
References
- https://github.com/gpac/gpac/commit/bd7fd6be546e0cd9e599c6b262c338c5f2ecec5c
- https://github.com/gpac/gpac/issues/3287
- https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/38/38_gf_media_import_media_tools_media_import_c_1297
- https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/38/README.md
- https://infosec.exchange/@sigdevel/116780566799952592