Impact
A buffer under-read in the gf_node_del function of GPAC's MP4Box component causes an out-of-bounds read that can expose internal memory contents. The flaw lies in the scenegraph/base_scenegraph.c file and is classified as a local memory read vulnerability (CWE‑119 and CWE‑125). An attacker who can control the environment and execute MP4Box locally may read restricted memory, potentially revealing sensitive data or affecting program stability.
Affected Systems
The vulnerability affects GPAC products, specifically MP4Box, in version 26.07.0. The fix is available in version abi‑16.23 or later. The affected vendor is GPAC. No other vendor or product variants are listed as impacted.
Risk and Exploitability
The CVSS score of 2.4 indicates low severity. The EPSS score is < 1%, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The exploit is publicly disclosed and requires local execution privileges; an attacker would need to run or influence MP4Box on the host. Because the flaw only allows a read, its impact is limited to potential memory data leakage and program instability, but the overall risk remains low for typical use cases.
OpenCVE Enrichment