CVE-2026-1417: GPAC filedump.c dump_isom_rtp null pointer dereference
A weakness has been identified in GPAC up to 2.4.0. Affected by this issue is the function dumpisomrtp of the file applications/mp4box/filedump.c. This manipulation causes null pointer dereference. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Patch name: f96bd57c3ccdcde4335a0be28cd3e8fe296993de. Applying a patch is the recommended action to fix this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1417?
CVE-2026-1417 has been classified as having a moderate severity due to its potential for local exploitation via null pointer dereference.
How do I fix CVE-2026-1417?
To mitigate CVE-2026-1417, users should upgrade GPAC to version 2.4.1 or later.
Who is affected by CVE-2026-1417?
CVE-2026-1417 affects users of GPAC versions up to and including 2.4.0.
What type of attack vector is associated with CVE-2026-1417?
CVE-2026-1417 requires local access to execute the specific functions that trigger the null pointer dereference.
What functionality is impacted by CVE-2026-1417?
CVE-2026-1417 specifically impacts the 'dump_isom_rtp' function in the 'filedump.c' file of the GPAC application.