Back

MEDIUM

GPAC MP4Box loader_bt.c gf_bt_report memory corruption

Published Sep 14, 2026

Description

A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version abi-16.23 is able to mitigate this issue. The patch is identified as afca1f1181668d85941d51ed1adf647807d5d975. It is suggested to upgrade the affected component.

Affected products

Remediation

No remediation recorded yet.

References (10)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner VulDB
Published Sep 14, 2026
Updated Sep 14, 2026
Reserved Sep 13, 2026

CISA Vulnrichment

Updated Sep 14, 2026

NVD

Status Deferred
Modified Sep 14, 2026

Red Hat

No data

ENISA EUVD

Assigner VulDB
Published Sep 14, 2026
Updated Sep 14, 2026

GitHub

No data