Description
Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the nhntdmx_process() function. Fixed in fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6.
Published: 2026-09-09
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A buffer overflow in the GPAC library allows an attacker to gain arbitrary code execution by supplying a crafted file that triggers the nhntdmx_process() function. The flaw can be exploited when GPAC processes input data containing an out‑of‑bounds write, potentially enabling the attacker to execute code with the privileges of the host process. This flaw directly jeopardizes confidentiality, integrity, and availability of affected systems.

Affected Systems

GPAC library versions released before commit fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6 are vulnerable. No specific version numbers were published, but any build that includes the pre‑commit code path for nhntdmx_process() is at risk.

Risk and Exploitability

The vulnerability is a classic buffer overflow (CWE‑120) that is exploitable during media file parsing. Because the function processes external input, the attack vector is likely remote via a crafted media file or similar data stream. The CVSS score of 8.4 indicates a high severity, and the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, but the potential for arbitrary code execution warrants immediate attention. The vulnerability remains unpatched in deployed binaries until the fix of commit fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6 is applied.

Generated by OpenCVE AI on September 21, 2026 at 05:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the patch from commit fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6 or upgrade GPAC to a version that contains this fix
  • Restrict the processing of untrusted media or isolate GPAC parsing components to contain the impact of an exploit
  • Validate that the vulnerable nhntdmx_process() path is no longer reachable by executing test harnesses with crafted input

Generated by OpenCVE AI on September 21, 2026 at 05:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in GPAC enabling arbitrary code execution via nhntdmx_process()

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Gpac
Gpac gpac
Vendors & Products Gpac
Gpac gpac

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in GPAC enabling arbitrary code execution via nhntdmx_process()
Weaknesses CWE-120

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the nhntdmx_process() function. Fixed in fac50e6a12ac27ffabdd5d3080b51afcc44ad8d6.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T14:47:54.111Z

Reserved: 2026-08-07T00:00:00.000Z

Link: CVE-2026-71612

cve-icon Vulnrichment

Updated: 2026-09-14T14:46:52.495Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T20:20:21.587

Modified: 2026-09-14T15:17:06.970

Link: CVE-2026-71612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T05:45:10Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')