在 GPAC(版本 f1219cde 及之前)中发现一个漏洞。受影响的是 MP4Box 组件中 文件里的 函数。该漏洞由对函数的特定操作触发,会导致可达到的断言失败(reachable assertion)。该攻击必须通过本地方式执行。利用代码已公开,并可能被实际使用。升级到 版本可以解决此问题。补丁的标识符为 。建议升级受影响的组件以修复此漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | GPAC | f1219cde |
cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90613 | 3.3 LOW | GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion |
| CVE-2026-90611 | 3.3 LOW | GPAC MP4Box loader_xmt.c xmt_parse_element assertion |
| CVE-2026-90610 | 3.3 LOW | GPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-read |
| CVE-2026-90609 | 3.3 LOW | GPAC MP4Box vrml_tools.c null pointer dereference |
No comments yet