Impact
A use‑after‑free vulnerability exists in the gf_inline_get_proto_lib function of GPAC’s Proto Link Handler. When invoked with manipulated input, this function can free a memory buffer and subsequently access it again, leading to memory corruption. The flaw is a classic buffer access error (CWE‑119) and a use‑after‑free condition (CWE‑416), which can result in application crash or unpredictable behavior.
Affected Systems
The vulnerability is present in GPAC 26.08-DEV. Upgrading to version abi-16.24 or newer mitigates this issue. No other vendor or product variants are listed.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is local; an attacker must have access to the system running GPAC to exploit it. Public exploits have been released, so a local attacker could trigger the use‑after‑free by providing a crafted media file. The vulnerability is not listed in CISA KEV.
OpenCVE Enrichment