Description
A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scene_manager/scene_dump.c of the component MP4Box. The manipulation leads to reachable assertion. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is able to address this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is advised.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via local assertion failure
Action: Immediate Patch
AI Analysis

Impact

Based on the description, it is inferred that manipulating the input processed by gf_sm_dump_command_list could trigger the assertion failure and cause the function to crash. The resulting crash produces a denial‑of‑service condition for any user or process running MP4Box on the affected system. This flaw does not provide remote code execution, escalated privileges, or data disclosure; it is limited to local denial of service.

Affected Systems

All releases of GPAC MP4Box up to commit f1219cde are affected. The issue is fixed starting with the abi‑16.23 release, which applies the commit identified by afca1f1181668d85941d51ed1adf647807d5d975. Systems running older versions of GPAC, particularly those that use MP4Box, should be considered vulnerable if they have not applied the patch or updated to abi‑16.23.

Risk and Exploitability

The CVSS score of 4.8 indicates a medium risk level, and the EPSS score is less than 1%, while the vulnerability is not listed in CISA’s KEV catalog. The flaw requires a local attacker with the ability to execute MP4Box to exploit the assertion failure, and the exploit is publicly available and might be used where privileged or local users have access to run MP4Box. The threat is limited to denial of service rather than more serious compromise.

Generated by OpenCVE AI on September 15, 2026 at 15:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to the abi‑16.23 release or apply the specific commit that fixes the assertion failure.
  • If an upgrade is not immediately feasible, restrict local execution of MP4Box by setting file permissions or running the binary in a sandbox or container so that untrusted users cannot trigger the crash.
  • Monitor application logs and system crash reports for assertion failures, and enact the patch or upgrade as soon as possible when the crash is observed to prevent repeat service interruptions.

Generated by OpenCVE AI on September 15, 2026 at 15:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scene_manager/scene_dump.c of the component MP4Box. The manipulation leads to reachable assertion. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is able to address this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is advised.
Title GPAC MP4Box scene_dump.c gf_sm_dump_command_list assertion
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-617
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:54:55.682Z

Reserved: 2026-09-12T19:39:21.169Z

Link: CVE-2026-90612

cve-icon Vulnrichment

Updated: 2026-09-14T15:53:41.068Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T02:17:15.533

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90612

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:45:19Z

Weaknesses