Description
Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the j2kdec_process() function. Fixed in 9a253a07fd3f6b48022bba74302bf39388dda859.
Published: 2026-09-09
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A buffer overflow in the GPAC media framework's j2kdec_process function permits attackers to execute arbitrary code on systems that process untrusted JPEG 2000 data. The overflow occurs when malformed data bypasses bounds checking, enabling the attacker to overwrite critical memory and gain full control over the process. This vulnerability directly leads to remote or local code execution depending on how the system invokes the decoder.

Affected Systems

GPAC, the open‑source multimedia framework, is affected. The flaw exists in the code identified by commit c2dee3aff638cd96f9617ac5b17dc2868cd90ef3. The security fix is applied in commit 9a253a07fd3f6b48022bba74302bf39388dda859. No vendor or version range is specified in the CVE entry, but any deployment using this version of GPAC is potentially vulnerable.

Risk and Exploitability

The CVSS score is 7.8 and EPSS is < 1%. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed active exploitation at the time of reporting. Exploitation would likely require the attacker to supply crafted JPEG 2000 data that is parsed by GPAC. Because this is a classic buffer overflow, the exploit can be processed, though techniques such as ASLR, stack canaries, and sandboxing may reduce the risk.

Generated by OpenCVE AI on September 10, 2026 at 23:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update GPAC to the fixed commit 9a253a07fd3f6b48022bba74302bf39388dda859 or a later release.
  • Modify any application that uses GPAC so it does not process untrusted JPEG 2000 data without additional validation or sandboxing.
  • If an immediate update is not possible, isolate the application in a sandboxed environment or restrict access to the decoder until the patch can be applied.

Generated by OpenCVE AI on September 10, 2026 at 23:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title Buffer Overflow in GPAC JPEG 2000 Decoder Enabling Arbitrary Code Execution

Thu, 10 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Title GPAC Buffer Overflow in j2kdec_process Allows Arbitrary Code Execution
Weaknesses CWE-787

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Gpac
Gpac gpac
Vendors & Products Gpac
Gpac gpac

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title GPAC Buffer Overflow in j2kdec_process Allows Arbitrary Code Execution
Weaknesses CWE-120
CWE-787

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the j2kdec_process() function. Fixed in 9a253a07fd3f6b48022bba74302bf39388dda859.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-10T15:15:11.787Z

Reserved: 2026-08-07T00:00:00.000Z

Link: CVE-2026-71613

cve-icon Vulnrichment

Updated: 2026-09-10T15:15:07.480Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T20:20:21.747

Modified: 2026-09-10T16:17:52.963

Link: CVE-2026-71613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T23:15:08Z

Weaknesses
  • CWE-120

    Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')