CVE-2026-90825
Deferred Deferred - Pending Action

Use After Free in GPAC MP4Box

Vulnerability report for CVE-2026-90825, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-15

Assigner: VulDB

Description

A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gf_node_unregister of the file scenegraph/base_scenegraph.c of the component MP4Box. The manipulation results in use after free. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is advised.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-15
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gpac mp4box From abi-16.23 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-416 The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CWE-119 The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a use-after-free issue in GPAC 26.07.0, specifically in the function gf_node_unregister within the file scenegraph/base_scenegraph.c of the MP4Box component. It allows an attacker with local access to exploit freed memory, potentially leading to arbitrary code execution or crashes.

Detection Guidance

This vulnerability is specific to GPAC 26.07.0 and involves a use-after-free issue in the MP4Box component. Detection requires checking the installed version of GPAC/MP4Box. Use commands like 'mp4box -version' or 'apt list --installed | grep gpac' to verify the version. If version 26.07.0 is detected, the system is vulnerable.

Impact Analysis

If exploited, this vulnerability could allow an attacker to execute arbitrary code, crash the application, or gain unauthorized access to the system. Since it requires local access, the risk is higher for users who have direct access to the affected system.

Compliance Impact

This vulnerability is a use-after-free issue in GPAC 26.07.0 that requires local access to exploit. It does not directly impact data confidentiality or integrity but could lead to system instability. Compliance with standards like GDPR or HIPAA typically focuses on data protection, which is not directly affected by this issue. However, system availability and integrity are minor concerns.

Mitigation Strategies

Upgrade GPAC to version abi-16.23 or later using your package manager (e.g., 'apt upgrade gpac' or 'yum update gpac'). Alternatively, apply the patch identified as 9eb40df4448b88d6a6ce3454657c06f47eff0b24 if available. Ensure no local untrusted users have access to execute MP4Box until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90825. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart