Description
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. It is possible to launch the attack remotely. Upgrading to version abi-16.26 is able to resolve this issue. The name of the patch is 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68. The affected component should be upgraded.
Published: 2026-09-18
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure/Denial of Service
Action: Apply patch
AI Analysis

Impact

This vulnerability arises from an out-of-bounds read in the function gf_rtp_parse_ttxt of the RTP Depacketizer component. By manipulating the argument size an attacker can cause the program to read memory beyond the buffer bounds. Although the description does not confirm code execution, a read of sensitive data or a crash could be induced, allowing remote exploitation through the RTP interface.

Affected Systems

It affects the GPAC media player library version 26.08-DEV. The flaw was fixed in the abi-16.26 release, which incorporates the commit 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68. Administrators using GPAC 26.08-DEV should upgrade to the patched version.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity, and the EPSS of less than 1 percent suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers would need network access to the RTP stream handler and could achieve memory disclosure or crash conditions. Prioritizing an update or patch is recommended.

Generated by OpenCVE AI on September 19, 2026 at 21:34 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade GPAC to release abi-16.26 or later, which includes the fix identified by commit 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68.
  • If an immediate upgrade is not possible, apply the patch locally by merging the commit into the source and rebuilding the binary to enforce proper bounds checking on argument sizes in gf_rtp_parse_ttxt.
  • Where neither patch nor upgrade can be applied, limit the component’s network exposure or disable RTP stream handling until a fix is available.

Generated by OpenCVE AI on September 19, 2026 at 21:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. It is possible to launch the attack remotely. Upgrading to version abi-16.26 is able to resolve this issue. The name of the patch is 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68. The affected component should be upgraded.
Title GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds
First Time appeared Gpac
Gpac gpac
Weaknesses CWE-119
CWE-125
CPEs cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
Vendors & Products Gpac
Gpac gpac
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-18T19:39:43.691Z

Reserved: 2026-09-17T17:33:55.195Z

Link: CVE-2026-93331

cve-icon Vulnrichment

Updated: 2026-09-18T19:39:39.117Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T02:17:08.780

Modified: 2026-09-18T20:17:31.950

Link: CVE-2026-93331

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T21:45:16Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-125

    Out-of-bounds Read