CVE-2026-90578: GPAC MP4Box list.c gf_list_count use after free
A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gflistcount of the file utils/list.c of the component MP4Box. Executing a manipulation can lead to use after free. The attack is restricted to local execution. The exploit has been published and may be used. Upgrading to version abi-16.23 can resolve this issue. This patch is called 49dee5cad329cfed310c1682703df7daa47df31a. It is suggested to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC MP4Box (utils/list.c, gf_list_count)to a version that resolves this vulnerability.Fixed in abi-16.23Patch 49dee5cad329cfed310c1682703df7daa47df31a
Event History
Frequently Asked Questions
Who is exposed to this issue?
Exposure is limited to systems running affected GPAC or MP4Box versions up to f1219cde where an attacker can execute code locally. The vulnerability is not described as remotely exploitable.
What level of access does an attacker need?
An attacker needs local execution and low privileges. No user interaction is required according to the supplied severity vector.
Is exploit code available?
Yes. The exploit has been published and may be used, which increases the urgency of remediation for systems where local access is possible.
How can the issue be remediated?
Upgrade the affected component to version abi-16.23. The referenced fix is patch 49dee5cad329cfed310c1682703df7daa47df31a.