CVE-2026-92473: GPAC BIFS commands.c gf_sg_command_del use after free
A vulnerability was identified in GPAC 26.08-DEV. The impacted element is the function gfsgcommanddel of the file src/scenegraph/commands.c of the component BIFS Handler. The manipulation leads to use after free. The attack needs to be performed locally. The exploit is publicly available and might be used. Upgrading to version abi-16.24 is sufficient to resolve this issue. The identifier of the patch is e34f4ba349d55cd1849f0bcf4cf46552732e2db7. It is suggested to upgrade the affected component.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC BIFS Handler (src/scenegraph/commands.c, gf_sg_command_del)to a version that resolves this vulnerability.Fixed in abi-16.24Patch e34f4ba349d55cd1849f0bcf4cf46552732e2db7 - Compensating control
Assume the exploit needs to be performed locally; restrict local access to the affected GPAC/BIFS Handler functionality to trusted users/systems.
Event History
Frequently Asked Questions
Who is realistically exposed to this issue?
Systems running the affected GPAC 26.08-DEV component are exposed if a local attacker has the required low-level privileges. The attack vector is local; the provided data does not indicate remote exploitation.
What access does an attacker need?
An attacker needs local access and low privileges. No user interaction is required, and the attack complexity is rated low.
What version resolves the vulnerability?
Upgrade the affected component to version abi-16.24 or later. The referenced fix is patch e34f4ba349d55cd1849f0bcf4cf46552732e2db7.
How urgent is remediation?
The severity is low with a CVSS score of 3.3, and the documented impact is limited to availability. However, public exploit availability is reported, so affected local installations should be upgraded.