Impact
The flaw resides in the GPAC MP4Box component, specifically in the gf_node_deactivate_ex function in base_scenegraph.c. This is a use‑after‑free (CWE‑416) that can also lead to out‑of‑bounds read or write (CWE‑119). A local attacker can manipulate a freed memory region, potentially corrupting data or achieving code execution. The description does not explicitly confirm execution, but the nature of the vulnerability indicates that memory corruption could be exploited for elevated local privileges or crash exploitation.
Affected Systems
The vulnerability affects GPAC (GPAC), specifically the MP4Box tool as shipped in version 26.07.0. The fix is included in the abi-16.23 release, and the patch commit identifier is 49dee5cad329cfed310c1682703df7daa47df31a.
Risk and Exploitability
With a CVSS score of 4.8 the severity is moderate, and the EPSS score is < 1%. The vulnerability requires local access and has a publicly available exploit, but it is not listed in the CISA KEV catalog. The risk is therefore confined to environments where the MP4Box tool can be executed by an untrusted user. Proper mitigation reduces the likelihood to zero by removing the vulnerable code.
OpenCVE Enrichment