CVE-2026-90825: GPAC MP4Box base_scenegraph.c gf_node_unregister use after free
A vulnerability was found in GPAC 26.07.0. Affected by this vulnerability is the function gfnodeunregister of the file scenegraph/basescenegraph.c of the component MP4Box. The manipulation results in use after free. The attack is only possible with local access. The exploit has been made public and could be used. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 9eb40df4448b88d6a6ce3454657c06f47eff0b24. Upgrading the affected component is advised.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC MP4Boxto a version that resolves this vulnerability.Fixed in abi-16.23Patch 9eb40df4448b88d6a6ce3454657c06f47eff0b24
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems using GPAC MP4Box version 26.07.0 are affected. Exploitation requires local access and low privileges; it is not described as remotely exploitable.
Is public exploit information available?
Yes. The exploit has been made public and could be used, which increases the practical relevance for environments where local users can access the affected component.
What version resolves the vulnerability?
Upgrading to version abi-16.23 addresses the issue. The identified patch is 9eb40df4448b88d6a6ce3454657c06f47eff0b24.