在 GPAC 版本 f1219cde 及更早版本中发现了一个漏洞。受此问题影响的组件是 MP4Box 中的 文件中的 函数。通过操纵该函数可导致触达断言失败(reachable assertion)。利用该漏洞需要本地访问权限。该利用方式已公开披露,并可能被用于攻击。升级到版本 可以解决此问题。补丁的标识符为 。建议升级受影响的组件以修复此问题。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | GPAC | f1219cde |
cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90687 | 6.3 MEDIUM | GPAC MP4Box base_scenegraph.c gf_node_changed_internal use after free |
| CVE-2026-90698 | 5.3 MEDIUM | memcached mcmc Tokenizer proto_text.c try_read_command_asciiauth out-of-bounds |
| CVE-2026-90686 | 5.3 MEDIUM | GPAC MP4Box loader_bt.c gf_bt_report memory corruption |
| CVE-2026-90683 | 3.3 LOW | GPAC MP4Box base_scenegraph.c gf_node_unregister assertion |
| CVE-2026-90613 | 3.3 LOW | GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion |
| CVE-2026-90612 | 3.3 LOW | GPAC MP4Box scene_dump.c gf_sm_dump_command_list assertion |
| CVE-2026-90611 | 3.3 LOW | GPAC MP4Box loader_xmt.c xmt_parse_element assertion |
| CVE-2026-90610 | 3.3 LOW | GPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-read |
| CVE-2026-90609 | 3.3 LOW | GPAC MP4Box vrml_tools.c null pointer dereference |
| CVE-2026-90684 | 2.8 LOW | GPAC MP4Box base_scenegraph.c gf_node_get_field_count assertion |
No comments yet