Executive brief
GPAC is a multimedia framework used for video streaming and media transcoding. MP4Box, a component of GPAC, contains a buffer over-read vulnerability in its SVG attribute handling that could allow a local attacker with access to craft malicious files to read sensitive data from memory or cause application crashes.
Technical details
A buffer over-read vulnerability exists in the gf_svg_attributes_copy function within scenegraph/svg_attributes.c of the MP4Box component. The vulnerability allows an attacker to read beyond allocated buffer boundaries when processing SVG attributes. This requires local access and a crafted input file. The vulnerability was patched in commit afca1f1181668d85941d51ed1adf647807d5d975 and is fixed in version abi-16.23 and later.
Affected products
- GPAC GPAC up to f1219cde
Timeline
- 2026-09-14: disclosed: Vulnerability published
- 2026-07-27: patched: Patch commit afca1f1181668d85941d51ed1adf647807d5d975