Impact
A vulnerability in GPAC MP4Box may trigger a use‑after‑free condition via manipulation of the gf_node_unregister function in base_scenegraph.c. When an attacker supplies a crafted media file, the function frees a node while other references still exist, resulting in memory corruption. This use‑after‑free flaw is reflected in the disclosed weakness (CWE‑416) and can potentially destabilize the MP4Box process.
Affected Systems
The issue affects all GPAC distributions up to commit f1219cde, including the MP4Box component. Updating to the abi‑16.23 release or any later version incorporates the patch that resolves the problem.
Risk and Exploitability
Based on the CVSS score of 5.3, the vulnerability is considered moderate. No EPSS data is provided, and it is not listed in CISA KEV. The exploit is public and can be executed remotely by feeding a crafted media file to MP4Box. The reported use‑after‑free indicates a path for potential exploitation, but the official description does not specify whether this results in code execution or denial of service.
OpenCVE Enrichment