Executive brief
GPAC is a multimedia framework used for video processing and transcoding. MP4Box is its command-line tool for manipulating media files. A flaw in DEF/USE scene graph parsing can cause a crash or potential memory corruption when processing malformed scene files, affecting media import workflows that handle untrusted content.
Technical details
A heap use-after-free vulnerability exists in the gf_node_get_name function within GPAC's base_scenegraph.c. The root cause is in the error-handling path of gf_bt_sf_node(): when node parsing fails, the partially constructed node is freed and unregistered, but the stale pointer remains in the parser's def_nodes list. Subsequent DEF/USE resolution calls gf_node_get_name() on the dangling pointer, triggering a use-after-free read. The attack vector is remote (processing untrusted BT scene files via MP4Box -add). The vulnerability can cause denial-of-service via crash, and potentially more severe memory corruption. The fix (commit 9eb40df4) removes the failed node from the def_nodes list before freeing it.
Affected products
- GPAC GPAC up to commit f1219cde; fixed in abi-16.23 (commit 9eb40df4)
Timeline
- 2026-09-14: disclosed: Published in NVD
- 2026-07-27: patched: Fix commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24