MEDIUM
GPAC MP4Box loader_bt.c gf_bt_report memory corruption
Published Sep 14, 2026
6.9
MEDIUMCVSS 4.0
EPSS 0.86%
Description
A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version abi-16.23 is able to mitigate this issue. The patch is identified as afca1f1181668d85941d51ed1adf647807d5d975. It is suggested to upgrade the affected component.
Affected products
-
Affected
- f1219cde
-
Unaffected
- abi-16.23
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-77205 Advisory
- https://github.com/Ech06/CVE_submit/blob/main/gpac_3798.md exploit
- https://github.com/gpac/gpac/ product
- https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975 patch
- https://github.com/gpac/gpac/issues/3798 issue-tracking
- https://github.com/gpac/gpac/releases/tag/abi-16.23 patch
- https://vuldb.com/cve/CVE-2026-90686 third-party-advisory
- https://vuldb.com/submit/914120 third-party-advisory
- https://vuldb.com/vuln/403219 vdb-entrytechnical-description
- https://vuldb.com/vuln/403219/cti signaturepermissions-required
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-77205 | Advisory | |
| https://github.com/Ech06/CVE_submit/blob/main/gpac_3798.md | exploit | |
| https://github.com/gpac/gpac/ | product | |
| https://github.com/gpac/gpac/commit/afca1f1181668d85941d51ed1adf647807d5d975 | patch | |
| https://github.com/gpac/gpac/issues/3798 | issue-tracking | |
| https://github.com/gpac/gpac/releases/tag/abi-16.23 | patch | |
| https://vuldb.com/cve/CVE-2026-90686 | third-party-advisory | |
| https://vuldb.com/submit/914120 | third-party-advisory | |
| https://vuldb.com/vuln/403219 | vdb-entrytechnical-description | |
| https://vuldb.com/vuln/403219/cti | signaturepermissions-required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Sep 14, 2026
Updated Sep 14, 2026
Reserved Sep 13, 2026
Link CVE-2026-90686
CISA Vulnrichment
Updated Sep 14, 2026
Red Hat
No data
GitHub
No data