← Back to CVE List
CVE-2026-92474NVD
Vulnerability Summary
A security flaw has been discovered in GPAC 26.08-DEV. This affects the function gf_inline_get_proto_lib of the file src/compositor/mpeg4_inline.c of the component Proto Link Handler. The manipulation results in use after free. The attack requires a local approach. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.24 mitigates this issue. The patch is identified as e34f4ba349d55cd1849f0bcf4cf46552732e2db7. Upgrading the affected component is recommended.
CVSS v4.0 Base Metrics — Score 4.8 (MEDIUM)
Attack VectorLocal
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredLow
User InteractionNone
Confidentiality (Vulnerable System)None
Integrity (Vulnerable System)None
Availability (Vulnerable System)Low
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 3.3 (LOW)
Attack VectorLocal
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
ConfidentialityNone
IntegrityNone
AvailabilityLow
Affected & Patched Versions
- n/a GPAC >= 26.08-DEV
Not provided by cveorg for this CVE.
External References
- https://vuldb.com/vuln/405733
- https://vuldb.com/vuln/405733/cti
- https://vuldb.com/cve/CVE-2026-92474
- https://vuldb.com/submit/941005
- https://github.com/gpac/gpac/issues/3829
- https://github.com/user-attachments/files/30635900/poc_01.zip
- https://github.com/gpac/gpac/commit/e34f4ba349d55cd1849f0bcf4cf46552732e2db7
- https://github.com/gpac/gpac/releases/tag/abi-16.24
- https://github.com/gpac/gpac/