CVE-2026-90613: GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion
A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stblGetSampleInfos of the file isomedia/stblread.c of the component MP4Box. The manipulation results in reachable assertion. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC MP4Box (MP4Box) stbl_GetSampleInfos / isomedia/stbl_read.cto a version that resolves this vulnerability.Fixed in abi-16.23Patch 49dee5cad329cfed310c1682703df7daa47df31a - Compensating control
Because the attack must be initiated from a local position, restrict local access to GPAC MP4Box/MP4Box execution environment to prevent untrusted local users from triggering the exploit.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running GPAC MP4Box with code at or before f1219cde are affected. Exploitation requires local access and low privileges, so it is most relevant where untrusted local users can invoke MP4Box or influence media files it processes.
What does an attacker need to exploit it?
An attacker needs a local position with low privileges and must be able to trigger the vulnerable stbl_GetSampleInfos code path in MP4Box. Public exploit code is available.
What is the impact of successful exploitation?
The reported outcome is a reachable assertion, with availability impact rated low. No confidentiality or integrity impact is reported.
What should be done to remediate the issue?
Upgrade GPAC MP4Box to version abi-16.23. The identified fix is patch 49dee5cad329cfed310c1682703df7daa47df31a.