CVE-2026-71614
Awaiting Analysis Awaiting Analysis - Queue

Arbitrary Code Execution in GPAC

Vulnerability report for CVE-2026-71614, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: MITRE

Description

An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the src/media_tools/dvb_mpe.c, descriptorTime_slice_fec_identifier() and gf_m2ts_ipdatagram_reader() components. Fixed in 0e4093392e1f847c90d20e031e893cd942fef938.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
gpac gpac From c2dee3a (exc)
gpac gpac 0e4093392e1f847c90d20e031e893cd942fef938

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an integer underflow flaw in the GPAC multimedia framework, specifically in the file src/media_tools/dvb_mpe.c. It occurs in the descriptorTime_slice_fec_identifier() function where an 8-bit descriptor length from a crafted DSM-CC INT table section is subtracted by 3 without proper validation. When the descriptor length is 1, this subtraction causes an integer underflow, leading to a crash or denial of service.

Detection Guidance

Detecting this vulnerability requires checking for vulnerable versions of GPAC and analyzing media files for malformed DSM-CC INT tables. Inspect GPAC installations for versions before the patched commit 0e4093392e1f847c90d20e031e893cd942fef938. Use tools like strings or hex editors to examine TS files for unusually large descriptor lengths or invalid values in the descriptorTime_slice_fec_identifier function.

Impact Analysis

An attacker could exploit this by tricking a user into opening a maliciously crafted TS (Transport Stream) file. This would cause the application to crash or become unresponsive, resulting in a denial of service. The vulnerability does not allow arbitrary code execution but can disrupt normal operations of the GPAC software.

Compliance Impact

This vulnerability could potentially impact compliance with GDPR and HIPAA by enabling denial-of-service attacks that disrupt the availability of systems processing multimedia content. If exploited, it may lead to unauthorized disruptions in services handling sensitive data, which could violate availability requirements under these regulations.

Mitigation Strategies

Immediately update GPAC to the latest patched version (commit 0e4093392e1f847c90d20e031e893cd942fef938 or later). Avoid processing untrusted TS files, especially those from unknown or untrusted sources. Implement network monitoring to detect and block malformed DSM-CC INT tables or suspicious TS file transfers.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71614. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart