CVE-2026-90610: GPAC MP4Box svg_attributes.c gf_svg_attributes_copy buffer over-read
A vulnerability was found in GPAC up to f1219cde. This affects the function gfsvgattributescopy of the file scenegraph/svgattributes.c of the component MP4Box. Performing a manipulation results in buffer over-read. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 mitigates this issue. The patch is named afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is recommended.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC MP4Boxto a version that resolves this vulnerability.Fixed in abi-16.23Patch afca1f1181668d85941d51ed1adf647807d5d975
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Only systems where an attacker has local access are exposed to exploitation. The affected component is MP4Box in GPAC versions up to f1219cde.
What level of access does an attacker need?
An attacker needs local access and low privileges. No user interaction is required.
Is public exploit information available?
Yes. The exploit has been made public and could be used.
What is the recommended remediation?
Upgrade the affected GPAC component to version abi-16.23. The mitigating patch is afca1f1181668d85941d51ed1adf647807d5d975.