Executive brief
GPAC is an open-source multimedia framework used for video streaming and transcoding. A use-after-free vulnerability in the MP4Box component (which processes multimedia files) could allow a local attacker to crash the application or potentially execute code by providing a specially crafted media file.
Technical details
A use-after-free vulnerability exists in the gf_node_deactivate_ex function in scenegraph/base_scenegraph.c of GPAC's MP4Box component. The vulnerability is triggered through local file processing and requires no authentication or network access. An attacker can craft a malicious multimedia file to trigger the use-after-free condition, potentially leading to denial of service or code execution. The vulnerability has been patched in commit 49dee5cad329cfed310c1682703df7daa47df31a, and users should upgrade to version abi-16.23 or later.
Affected products
- GPAC MP4Box 26.07.0
Timeline
- 2026-09-14: disclosed
- 2026-07-28: patched: Patch commit 49dee5cad329cfed310c1682703df7daa47df31a