Impact
The vulnerability arises in GPAC version 26.08‑DEV in the gf_sg_command_del function of the BIFS Handler. It allows a use‑after‑free condition when manipulating commands, which can lead to memory corruption. The effect could be a crash or potential arbitrary code execution if a local attacker can control the data fed to gpac. The CVSS score is 4.8, indicating a moderate severity, but the exploit requires local access and the publicly available proof‑of‑concept demonstrates the possibility of exploitation. This weakness is classified as CWE‑119 and CWE‑416.
Affected Systems
The affected product is GPAC, a multimedia framework, at least the 26.08‑DEV build. No version range is provided beyond this build, and the vendor indicates that upgrading to the abi‑16.24 release, which includes the patch identified by commit e34f4b..., resolves the issue. There are no known impacts on other GPAC versions. The affected component is the BIFS Handler within the scenegraph/commands.c file.
Risk and Exploitability
The risk level is moderate. The exploit requires local execution; it is not remotely reachable and is not listed in CISA's KEV catalog. The EPSS score of less than 1 % indicates a very low probability of exploitation in the wild. Nevertheless, because the publicly available proof‑of‑concept is available and the flaw can lead to memory corruption, any local user who can run gpac with untrusted data should be considered a potential threat vector. An attacker would need to supply a crafted BIFS file or otherwise influence the command deletion logic to trigger the use‑after‑free. No elevated privileges are required beyond the user running gpac.
OpenCVE Enrichment