Description
A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the component Proto Link Handler. The manipulation results in use after free. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.24 mitigates this issue. The patch is identified as e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Upgrading the affected component is recommended.
Published: 2026-09-16
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Use After Free
Action: Patch
AI Analysis

Impact

A use‑after‑free vulnerability exists in the gf_inline_get_proto_lib function of GPAC’s Proto Link Handler. When invoked with manipulated input, this function can free a memory buffer and subsequently access it again, leading to memory corruption. The flaw is a classic buffer access error (CWE‑119) and a use‑after‑free condition (CWE‑416), which can result in application crash or unpredictable behavior.

Affected Systems

The vulnerability is present in GPAC 26.08-DEV. Upgrading to version abi-16.24 or newer mitigates this issue. No other vendor or product variants are listed.

Risk and Exploitability

The CVSS score of 4.8 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is local; an attacker must have access to the system running GPAC to exploit it. Public exploits have been released, so a local attacker could trigger the use‑after‑free by providing a crafted media file. The vulnerability is not listed in CISA KEV.

Generated by OpenCVE AI on September 18, 2026 at 06:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the GPAC abi-16.24 update or newer to remove the use after free flaw
  • If an update cannot be applied immediately, restrict GPAC from processing untrusted or externally supplied media files and run the process with the least privilege required
  • Monitor system logs and crash reports for signs of memory corruption or unexpected failures caused by the exploit

Generated by OpenCVE AI on September 18, 2026 at 06:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the component Proto Link Handler. The manipulation results in use after free. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.24 mitigates this issue. The patch is identified as e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Upgrading the affected component is recommended.
Title GPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after free
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-416
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-17T16:12:26.239Z

Reserved: 2026-09-16T12:14:58.989Z

Link: CVE-2026-92474

cve-icon Vulnrichment

Updated: 2026-09-17T16:12:16.355Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T20:17:48.610

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-92474

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T07:00:06Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free