Description
An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the src/media_tools/dvb_mpe.c, descriptorTime_slice_fec_identifier() and gf_m2ts_ipdatagram_reader() components. Fixed in 0e4093392e1f847c90d20e031e893cd942fef938.
Published: 2026-09-09
Score: 8.4 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

GPAC, an open‑source multimedia framework, has a vulnerability in its DVB‑MPE processing component that allows an attacker to execute arbitrary code. The flaw exists in the descriptorTime_slice_fec_identifier() and gf_m2ts_ipdatagram_reader() functions where improper handling of input data can lead to code injection via malformed descriptors (CWE‑94). When triggered, the attacker can run malicious code with the privileges of the GPAC process, effectively compromising the host system.

Affected Systems

Any installation of GPAC built from source or distributed binaries prior to commit 0e4093392e1f847c90d20e031e893cd942fef938, which introduced the fix. No vendor product list is available in the CNA data, so the affected systems are any GPAC installations before that commit.

Risk and Exploitability

The CVSS score of 8.4 denotes a high severity risk for arbitrary code execution. The EPSS score is reported as less than 1%, indicating that exploitation is currently rare, and the vulnerability is not listed in CISA’s KEV catalog. Attacks require a specially crafted media payload delivered to a system running GPAC, either locally or via a network channel; the flaw does not rely on unauthenticated network services but can be exploited once the file is processed.

Generated by OpenCVE AI on September 21, 2026 at 07:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update GPAC to commit 0e4093392e1f847c90d20e031e893cd942fef938 or a newer release that contains the fix
  • Avoid processing media files from untrusted sources until a patched version is deployed
  • If upgrading immediately is not feasible, run GPAC with the least privileges necessary and monitor for anomalous activity

Generated by OpenCVE AI on September 21, 2026 at 07:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Title GPAC Vulnerability Allows Arbitrary Code Execution via Malformed DVB-MPE Descriptors

Mon, 21 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title GPAC Media Tool Arbitrary Code Execution Vulnerability
Weaknesses CWE-119
CWE-470

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 11 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
First Time appeared Gpac
Gpac gpac
Vendors & Products Gpac
Gpac gpac

Wed, 09 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Title GPAC Media Tool Arbitrary Code Execution Vulnerability
Weaknesses CWE-119
CWE-470

Wed, 09 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the src/media_tools/dvb_mpe.c, descriptorTime_slice_fec_identifier() and gf_m2ts_ipdatagram_reader() components. Fixed in 0e4093392e1f847c90d20e031e893cd942fef938.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T12:19:01.669Z

Reserved: 2026-08-07T00:00:00.000Z

Link: CVE-2026-71614

cve-icon Vulnrichment

Updated: 2026-09-14T12:17:30.430Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T20:20:21.870

Modified: 2026-09-14T13:18:43.990

Link: CVE-2026-71614

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T07:45:11Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')