Description
A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack is restricted to local execution. The exploit has been published and may be used. Upgrading to version abi-16.23 can resolve this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.
Published: 2026-09-13
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free leading to local memory corruption
Action: Update Immediately
AI Analysis

Impact

A flaw exists in the GPAC MP4Box component's list.c utility, where the gf_list_count function can be used after freeing. When an attacker supplies crafted input, the function can access freed memory, resulting in a use-After-Free that may corrupt memory or crash the process. The problem is, but local memory corruption can enable partial or full compromise of the vulnerable system. This weakness is classed as CWE-119 and CWE-416.

Affected Systems

The vulnerability affects the GPAC MP4Box software distributed as the GPAC project. All versions prior to the patch commit 49dee5cad329cfed310c1682703df7daa47df31a (referenced by release abi-16.23) are susceptible. Systems that run GPAC for media processing or packaging should determine whether the installed binary matches the affected commit and plan to upgrade accordingly.

Risk and Exploitability

With a CVSS score of 4.8, the vulnerability is considered moderate. The EPSS score is < 1%, indicating, and the vulnerability is not listed in CISA's KEV catalog. Because the attack requires local access and the exploit has already been published, the risk to environments where GPAC processes untrusted input files is non-negligible. Prompt patching reduces the chance of exploitation.

Generated by OpenCVE AI on September 15, 2026 at 16:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch by upgrading GPAC to version abi-16.23 or later, which incorporates the commit that fixes the use-After-FREE.
  • If patching cannot occur immediately, restrict the use of GPAC MP4Box to internal, trusted workflows the patch or restriction is in place, monitor system logs for abnormal crashes or memory errors that may indicate attempted exploitation.
  • Execute untrusted media input processing in isolated containers or sandboxed environments to prevent direct interaction with the vulnerable GPAC binaries.

Generated by OpenCVE AI on September 15, 2026 at 16:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack is restricted to local execution. The exploit has been published and may be used. Upgrading to version abi-16.23 can resolve this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.
Title GPAC MP4Box list.c gf_list_count use after free
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-416
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 4.3, 'vector': 'AV:L/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T18:03:47.143Z

Reserved: 2026-09-12T16:34:13.850Z

Link: CVE-2026-90578

cve-icon Vulnrichment

Updated: 2026-09-15T18:03:25.286Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T19:16:53.350

Modified: 2026-09-15T19:17:45.770

Link: CVE-2026-90578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T16:45:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free