Impact
The vulnerability originates in the gf_node_unregister routine within GPAC MP4Box’s base_scenegraph.c, where a freed memory block can still be accessed. This use‑after‑free condition can lead to memory corruption or a crash when the freed memory is referenced again. The effect is limited to the process memory; no specific privilege escalation or remote impact is described. The weakness is categorized under CWE‑119 and CWE‑416.
Affected Systems
GPAC version 26.07.0, specifically the MP4Box component, is affected. The issue is resolved in release abi‑16.23, which incorporates the patch identified by commit 9eb40df4448b88d6a6ce3454657c06f47eff0b24. All distributions of GPAC that bundle the 26.07.0 version of MP4Box are vulnerable until updated.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The EPSS score is less than 1%, indicating a very low probability that the vulnerability is being exploited in the wild. The flaw requires local access; no remote exploitation path is described. A public exploit is available, which a local attacker could use to trigger a use‑after‑free that may lead to a crash. The overall risk is confined to environments where GPAC is running and processes untrusted input.
OpenCVE Enrichment