Impact
The vulnerability occurs in the gf_node_changed_internal function of the GPAC MP4Box component. It results in a use‑after‑free condition that can be exploited from a remote source. Public disclosures indicate that attackers can leverage this flaw, though the exact outcomes (such as remote code execution) are not specified in the available data.
Affected Systems
GPAC users running GPAC MP4Box versions up to commit f1219cde are impacted. The issue is fixed in the abi-16.23 release, which applies the patch identified by commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate severity. The EPSS score is < 1%, indicating a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Because the exploit is publicly available and can be initiated remotely, the risk of exploitation remains non‑negligible, especially in environments that use the affected GPAC component.
OpenCVE Enrichment