Description
A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 can resolve this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. The affected component should be upgraded.
Published: 2026-09-14
Score: 2.4 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service via assertion failure
Action: Update
AI Analysis

Impact

The vulnerability in GPAC MP4Box arises when the function lsr_exec_command_list processes certain input, causing a reachable assertion in the file laser/lsr_dec.c. This assertion failure indicates that an invalid condition can be triggered by crafted input. The immediate consequence is a denial of service of the MP4Box utility, and any downstream processes relying on it. The likely attack vector is a local user invoking MP4Box with malicious arguments, as the vulnerability requires local access to trigger the assertion.

Affected Systems

GPAC, the open-source multimedia framework, is impacted up through the commit identified by f1219cde, including all releases prior to abi-16.23. The affected component is the MP4Box tool. Users running any legacy GPAC build that has not incorporated the patch commit afca1f1181668d85941d51ed1adf647807d5d975 are susceptible.

Risk and Exploitability

The CVSS score of 2.4 places the defect in the low-severity range, reflecting that the control requires local user access and the outcome is limited to a crash rather than arbitrary code execution. The EPSS score is <1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. Nevertheless, local attackers who can invoke MP4Box with crafted parameters could trigger the assertion, forcing the service to stop. The lack of network exposure and the low severity reduce the urgency, yet the failure to validate input remains a concern. The likely attack vector is local execution of MP4Box with malicious input, as inferred from the description.

Generated by OpenCVE AI on September 15, 2026 at 15:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official update to version abi-16.23 or newer, which includes the patch commit afca1f1181668d85941d51ed1adf647807d5d975.
  • If you are using source builds, verify that the source tree contains the commit afca1f1181668d85941d51ed1adf647807d5d975 and rebuild MP4Box.
  • Restrict local users’ ability to execute MP4Box with arbitrary arguments by using file permissions or SELinux contexts; only allow trusted administrators or services to run it.

Generated by OpenCVE AI on September 15, 2026 at 15:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in GPAC up to f1219cde. Affected by this issue is the function lsr_exec_command_list of the file laser/lsr_dec.c of the component MP4Box. The manipulation leads to reachable assertion. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 can resolve this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. The affected component should be upgraded.
Title GPAC MP4Box lsr_dec.c lsr_exec_command_list assertion
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-617
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 2.8, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 2.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 2.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-16T14:44:37.246Z

Reserved: 2026-09-13T04:55:31.800Z

Link: CVE-2026-90685

cve-icon Vulnrichment

Updated: 2026-09-16T14:44:32.791Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T06:16:58.300

Modified: 2026-09-16T15:18:38.217

Link: CVE-2026-90685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses