Impact
GPAC’s MP4Box component contains a use‑after‑free flaw in the gf_node_deactivate_ex function located in base_scenegraph.c. The bug occurs when the function frees a node that is still referenced elsewhere, allowing an attacker to corrupt memory or cause a crash by supplying crafted data to the function. The vulnerability is a classic buffer over‑read/over‑write (CWE‑119) coupled with improper memory reuse (CWE‑416), and it can be triggered locally by processing malicious media files.
Affected Systems
All installations of GPAC built from the 26.08‑DEV source or earlier releases that include MP4Box are affected. The fix is delivered in the abi‑16.24 release and the specific commit e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Any version prior to abi‑16.24 that runs MP4Box is vulnerable, including the default binary distribution of GPAC.
Risk and Exploitability
The CVSS score of 4.8 places the vulnerability in the low‑to‑moderate range, and the EPSS score of less than 1 % indicates an extremely low overall exploitation probability at the time of this analysis. The flaw is not listed in CISA’s KEV catalog. Attackers must have local access or be able to supply malicious media files to a local instance of MP4Box, so the risk is confined to local users or services that automatically process untrusted media. No remote execution vector is known.
OpenCVE Enrichment