Executive brief
GPAC is an open-source multimedia framework used for video streaming, transcoding, and packaging. MP4Box, a component of GPAC, contains a vulnerability in scene dump functionality that can be triggered by a specially crafted local input, causing an assertion failure that could lead to a denial of service.
Technical details
The vulnerability is a reachable assertion in the gf_sm_dump_command_list function within the scene_manager/scene_dump.c file of GPAC's MP4Box component. The flaw can be triggered through local manipulation of scene dump processing, affecting versions up to f1219cde. This is not a memory corruption issue but rather a logic error that triggers an assertion check. The attack requires local access and does not require elevated privileges. The issue was patched in commit afca1f1181668d85941d51ed1adf647807d5d975 included in version abi-16.23.
Affected products
- GPAC GPAC up to f1219cde
Timeline
- 2026-09-14: disclosed
- 2026-07-27: patched: Patch commit afca1f1181668d85941d51ed1adf647807d5d975