Impact
GF_NODE_UNREGISTER reaches an assertion in base_scenegraph.c, causing the GPAC MP4Box component to crash when an attacker manipulates input. This failure does not compromise confidentiality or integrity but disrupts functionality, which can be interpreted as a denial of service. The flaw stems from an unchecked return value leading to an unexpected assertion failure, classified as CWE‑617.
Affected Systems
GPAC, the multimedia framework that includes the MP4Box component, is vulnerable in all releases up to the commit f1219cde. Users running any of those versions can be affected. The official fix is available in version abi‑16.23, where the problematic assertion logic has been removed or protected.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. Exploitation requires local access to the machine running GPAC, meaning only users or processes with write capabilities on the local system can trigger the assertion. No public exploit is listed in the CISA KEV catalog, and the EPSS score is < 1% (0.00118), indicating a low but non‑zero probability of exploitation. The threat is not actively exploited at a large scale.
OpenCVE Enrichment