CVE-2026-90793: GPAC MP4Box base_scenegraph.c gf_node_get_name use after free
A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gfnodegetname of the file scenegraph/basescenegraph.c of the component MP4Box. Such manipulation leads to use after free. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. Upgrading to version abi-16.23 is recommended to address this issue. The name of the patch is 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is advised.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC MP4Boxto a version that resolves this vulnerability.Fixed in abi-16.23Patch 9eb40df4448b88d6a6ce3454657c06f47eff0b24
Event History
Frequently Asked Questions
What conditions are required for exploitation?
The attack can be performed remotely and requires no privileges, but it requires user interaction. The disclosed exploit may be used.
Which releases should be considered affected?
GPAC MP4Box versions up to f1219cde are affected. Upgrading to version abi-16.23 is recommended.
What should be done if an affected installation is identified?
Upgrade the affected GPAC MP4Box component to abi-16.23. The referenced patch is 9eb40df4448b88d6a6ce3454657c06f47eff0b24.