Impact
The vulnerability is a null pointer dereference in the gf_node_list_add_child function within GPAC’s MP4Box component, triggered when a null child node is added to the scene graph. This flaw causes the application to crash, resulting in a denial of service for the local user executing the code, but it does not provide any remote code execution capability.
Affected Systems
Affected product is GPAC MP4Box as distributed by the GPAC project. Versions up to commit f121 incorporated in version abi‑16.23 and later, which applies commit 49dee5cad329cfed310c1682703df7daa47df31a.
Risk and Exploitability
The CVSS score of 4.8 indicates a medium risk level, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is local only and requires the attacker to have the ability to invoke the function with a null child. While the exploit has been publicly a crafted input or action within the application, making it unlikely to be widely exploited in in the CISA KEV catalog further reduces the perceived threat but does not eliminate the need for remediation.
OpenCVE Enrichment