Impact
This flaw resides in the GPAC Compositor’s gf_mo_get_od_id function in media_object.c. The vulnerability is a use‑after‑free that can be triggered by manipulating media objects. If successfully exploited, the attacker can corrupt memory and potentially execute arbitrary code. The description states that the flaw is remotely exploitable and been published.
Affected Systems
GPAC versions up to commit f1219cde are affected. The issue is fixed in the abi‑16.24 release, which includes commit e34f4ba349d55cd1849f0bcf4cf46552732e2 binaries must upgrade to this release to remediate the flaw.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS is below 1 %, so the overall likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, because the attack can be performed remotely and exploits are available, the risk remains non‑negligible for exposed systems.
OpenCVE Enrichment