Executive brief
GPAC is an open-source multimedia framework used to process audio and video files. A stack buffer overflow in the NHNT (Networked Hint Track) file handler allows an attacker to crash the application or execute arbitrary code by providing a file with an excessively long path exceeding 1000 bytes. Exploitation requires only the ability to place a file at a crafted path or convince a user to open one.
Technical details
The vulnerability is a stack buffer overflow in the nhntdmx_process() function in dmx_nhnt.c. The root cause is a logic flaw in path validation: a 1000-byte stack buffer (szMedia) is initially filled safely using strncpy, but later the code uses an unsafe strcpy to re-copy the original untruncated file path into the buffer at line 379. The length check at line 323 operates on a strrchr-truncated version of the path (after extension removal), not the original path, rendering it ineffective. An attacker crafting a path longer than 1000 bytes with an early dot character (e.g., "a.bbb/d1/d2/...") bypasses validation and triggers overflow. The attack surface includes any use of GPAC's NHNT processing: the command-line tool, MP4Box, or applications using libgpac. The vulnerability was fixed in commit fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6 by replacing the unsafe strcpy with gf_strlcpy.
Affected products
- GPAC GPAC prior to fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6 (commit c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 and earlier)
Timeline
- 2026-06-09: disclosed: Issue #3612 opened on GitHub
- 2026-09-09: patched: Fix released in commit fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6
- 2026-09-09: advisory: CVE-2026-71612 published