Junglewise Threat Intelligence

CVE-2026-71612: GPAC buffer overflow in nhntdmx_process via long file path

CVE-2026-71612 · Severity: high · CVSS 8.4 · Published 2026-09-09

Technologies: Gpac. Vendors: Gpac.

Executive brief

GPAC is an open-source multimedia framework used to process audio and video files. A stack buffer overflow in the NHNT (Networked Hint Track) file handler allows an attacker to crash the application or execute arbitrary code by providing a file with an excessively long path exceeding 1000 bytes. Exploitation requires only the ability to place a file at a crafted path or convince a user to open one.

Technical details

The vulnerability is a stack buffer overflow in the nhntdmx_process() function in dmx_nhnt.c. The root cause is a logic flaw in path validation: a 1000-byte stack buffer (szMedia) is initially filled safely using strncpy, but later the code uses an unsafe strcpy to re-copy the original untruncated file path into the buffer at line 379. The length check at line 323 operates on a strrchr-truncated version of the path (after extension removal), not the original path, rendering it ineffective. An attacker crafting a path longer than 1000 bytes with an early dot character (e.g., "a.bbb/d1/d2/...") bypasses validation and triggers overflow. The attack surface includes any use of GPAC's NHNT processing: the command-line tool, MP4Box, or applications using libgpac. The vulnerability was fixed in commit fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6 by replacing the unsafe strcpy with gf_strlcpy.

Affected products

  • GPAC GPAC prior to fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6 (commit c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 and earlier)

Timeline

  • 2026-06-09: disclosed: Issue #3612 opened on GitHub
  • 2026-09-09: patched: Fix released in commit fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6
  • 2026-09-09: advisory: CVE-2026-71612 published

References

Related threats