Impact
A heap-based buffer overflow occurs in the rmt_client_handle_ws_frame function of GPAC's WebSocket handler when the argument payload_size is manipulated. The flaw can allow an attacker to overwrite memory on the heap, leading to arbitrary code execution or a crash, thereby compromising confidentiality, integrity, and availability. The weakness is a classic buffer overflow, classified under CWE-119 and CWE-122.
Affected Systems
GPAC (GPAC multimedia framework) version 26.07.0 is affected. The upstream patch, identified by commit 37bccbb30cf53a0e1a084cea9a1ce422b3ddfe12, is included in release abi-16.26. Any installation running the vulnerable version should be upgraded to abi-16.26 or apply the specific commit.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate risk; the EPSS score is below 1%, meaning the probability of exploitation is currently very low. However, the vulnerability can be triggered remotely via malicious WebSocket frames, and the exploit has been publicly disclosed. The vulnerability is not currently listed in the CISA KEV catalog, but administrators should consider it in risk assessments.
OpenCVE Enrichment