Junglewise Threat Intelligence

CVE-2026-90793: GPAC MP4Box heap use-after-free in gf_node_get_name

CVE-2026-90793 · Severity: medium · CVSS 5.4 · Published 2026-09-14

Technologies: Gpac. Vendors: Gpac.

Executive brief

GPAC is a multimedia framework used for video processing and transcoding. MP4Box is its command-line tool for manipulating media files. A flaw in DEF/USE scene graph parsing can cause a crash or potential memory corruption when processing malformed scene files, affecting media import workflows that handle untrusted content.

Technical details

A heap use-after-free vulnerability exists in the gf_node_get_name function within GPAC's base_scenegraph.c. The root cause is in the error-handling path of gf_bt_sf_node(): when node parsing fails, the partially constructed node is freed and unregistered, but the stale pointer remains in the parser's def_nodes list. Subsequent DEF/USE resolution calls gf_node_get_name() on the dangling pointer, triggering a use-after-free read. The attack vector is remote (processing untrusted BT scene files via MP4Box -add). The vulnerability can cause denial-of-service via crash, and potentially more severe memory corruption. The fix (commit 9eb40df4) removes the failed node from the def_nodes list before freeing it.

Affected products

  • GPAC GPAC up to commit f1219cde; fixed in abi-16.23 (commit 9eb40df4)

Timeline

  • 2026-09-14: disclosed: Published in NVD
  • 2026-07-27: patched: Fix commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24

References

Related threats