Executive brief
GPAC is an open-source multimedia toolkit used for video processing and transcoding. A null pointer dereference vulnerability in the MP4Box component allows a local attacker with access to craft malicious media files to crash the application, causing denial of service.
Technical details
The vulnerability is a null pointer dereference (CWE-476) in an unknown function within scenegraph/vrml_tools.c of the MP4Box component. The defect arises from insufficient null-pointer validation in VRML scene graph processing. Attack requires local file system access to provide a specially crafted input file to the application. Successful exploitation results in application crash and denial of service. The vulnerability was patched in commit 49dee5cad329cfed310c1682703df7daa47df31a, available in version abi-16.23 or later.
Affected products
- GPAC GPAC up to f1219cde
Timeline
- 2026-09-14: disclosed
- 2026-07-28: patched: Fix available in commit 49dee5cad329cfed310c1682703df7daa47df31a and version abi-16.23