Impact
The flaw is a stack-based buffer overflow in the gf_sg_dom_event_bubble function of the MP4Box component in GPAC version 26.07.0. When this function processes specially crafted input, the buffer is overrun, potentially allowing an attacker to overwrite the stack and execute arbitrary code or crash the process. The vulnerability is classified as local, requiring the attacker to.
Affected Systems
It affects the GPAC project’s MP4Box utility. The issue exists in the 26.07.0 release and has been fixed in the abi-16.23 release. The patch identifier is 9eb40df4448b88d6a6ce3454657c06f47eff0b24. All GPAC products identified by the CPE string are potentially affected if they include the vulnerable version.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Since the exploit is local only, the risk is limited to users who can run MP4Box with untrusted data. The stack overflow could lead to code execution or denial of service if an attacker controls input. The risk remains moderate but could be high if local privilege is available. The publicly disclosed exploit means the vulnerability can be used if the local environment is compromised.
OpenCVE Enrichment