Description
A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component.
Published: 2026-09-14
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an assertion failure inside the function stbl_GetSampleInfos of GPAC’s MP4Box, triggered by malformed MP4 input. Failure of the assertion leads to an abort of the process, causing the application to crash. No evidence of code execution or privilege escalation is provided, so the primary consequence is service interruption for the local user running the program.

Affected Systems

All versions of GPAC before the commit that introduced the fix (f1219cde) are affected, including releases prior to abi‑16.23. The product in question is the MP4Box component of GPAC. Users on older builds that expose MP4Box to untrusted files are at risk.

Risk and Exploitability

The CVSS score of 4.8 indicates low to moderate severity. Exploitation requires local access; an attacker must supply a crafted MP4 file to trigger the assertion. Public exploits have already been released, but the EPSS score of <1% suggests a very low probability of widespread exploitation. The vulnerability is not listed in CISA’s KEV catalog.

Generated by OpenCVE AI on September 15, 2026 at 15:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to abi‑16.23 or a later release to receive the assertion‑failure fix.
  • If an immediate upgrade is unavailable, run MP4Box in a restricted environment or only allow it to process trusted MP4 files, thereby preventing local attackers from submitting malicious input.
  • Monitor application logs for crashes or assertion failures, and apply additional input validation or filtering for MP4 files if the component must remain exposed to untrusted data.

Generated by OpenCVE AI on September 15, 2026 at 15:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component.
Title GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-617
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:38:55.273Z

Reserved: 2026-09-12T19:39:24.362Z

Link: CVE-2026-90613

cve-icon Vulnrichment

Updated: 2026-09-16T14:38:42.711Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T02:17:15.690

Modified: 2026-09-16T15:18:34.507

Link: CVE-2026-90613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:45:19Z

Weaknesses