Executive brief
GPAC is a multimedia framework used for video streaming and transcoding. A stack-based buffer overflow vulnerability in the scenegraph module can be triggered through specially crafted multimedia files, potentially leading to code execution or application crash on affected systems.
Technical details
A stack-based buffer overflow vulnerability exists in the gf_node_activate_ex function within scenegraph/base_scenegraph.c in GPAC up to commit f1219cde. The vulnerability can be exploited locally through the processing of malicious multimedia input. An attacker can trigger the overflow by supplying crafted scenegraph data, which may result in arbitrary code execution or denial of service. The vulnerability has been patched in version abi-16.23 via commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24.
Affected products
- GPAC GPAC up to f1219cde
Timeline
- 2026-09-15: disclosed
- 2026-07-27: patched: Patch commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24