Executive brief
GPAC is an open-source multimedia framework used for video streaming and transcoding. A use-after-free memory vulnerability exists in the BIFS scene graph handler, which could allow a local attacker to trigger a crash or potentially execute code by processing a specially crafted multimedia file.
Technical details
A use-after-free vulnerability exists in the gf_sg_command_del function of src/scenegraph/commands.c within the BIFS Handler component of GPAC 26.08-DEV. The vulnerability is triggered through local manipulation of the scenegraph command processing logic. The attack vector is local and does not require special privileges or network access. An attacker can exploit this by providing a malicious input file to trigger memory access violations. A patch is available in version abi-16.24 (commit e34f4ba349d55cd1849f0bcf4cf46552732e2db7).
Affected products
- GPAC Project GPAC 26.08-DEV
Timeline
- 2026-09-16: disclosed
- 2026-08-03: patched: Fix available in abi-16.24