Executive brief
GPAC is an open-source multimedia framework used for video streaming, transcoding, and packaging. A null pointer dereference vulnerability in the MP4Box tool's scene graph handling can cause a local denial of service. An attacker with local access to a system running a vulnerable version could crash the application or potentially trigger unintended behavior.
Technical details
The vulnerability is a null pointer dereference in the gf_sg_mfurl_del function located in scenegraph/vrml_tools.c within the MP4Box component of GPAC. The issue affects builds up to commit f1219cde and requires local access to exploit. The flaw can be triggered through fuzzing or crafted input to the affected function, leading to application crash. The issue is fixed in commit 49dee5cad329cfed310c1682703df7daa47df31a and is available in version abi-16.23 or later of GPAC's rolling release.
Affected products
- GPAC GPAC up to commit f1219cde
Timeline
- 2026-09-13: disclosed
- 2026-07-28: patched: Patch commit 49dee5cad329cfed310c1682703df7daa47df31a