CVE-2026-79513: Medium severity Gpac GPAC vulnerability
A divide-by-zero vulnerability in the gfdashgettimelineduration function (src/mediatools/dashclient.c) of GPAC v26.07.0 allows attackers to cause a Denial of Service (DoS) via a crafted MPD SegmentTimeline. Fixed in 2fd5a06ab226767900fd86edb5a1e8bfc1010640.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPACto a version that resolves this vulnerability.Patch 2fd5a06ab226767900fd86edb5a1e8bfc1010640
Event History
Frequently Asked Questions
What must an attacker provide to trigger the denial of service?
The attacker must cause GPAC to process a crafted MPD containing a malicious SegmentTimeline. Exploitation requires user interaction, as reflected by the UI:R vector.
What is the impact of successful exploitation?
Successful exploitation causes a divide-by-zero condition in gf_dash_get_timeline_duration and can deny service. The provided vector indicates availability impact only, with no confidentiality or integrity impact.
Which release is identified as affected, and is a fix available?
GPAC v26.07.0 is identified as affected. The issue is fixed by commit 2fd5a06ab226767900fd86edb5a1e8bfc1010640.