CVE-2026-93331: GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds
A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gfrtpparsettxt of the file src/ietf/rtpdepacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. It is possible to launch the attack remotely. Upgrading to version abi-16.26 is able to resolve this issue. The name of the patch is 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68. The affected component should be upgraded.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC RTP Depacketizerto a version that resolves this vulnerability.Fixed in abi-16.26Patch 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68
Event History
Frequently Asked Questions
What input does an attacker need to control?
An attacker needs to manipulate the size argument processed by the RTP Depacketizer's gf_rtp_parse_ttxt function. The issue can be triggered remotely and does not require privileges or user interaction according to the supplied severity vector.
Which versions should be remediated?
GPAC 26.08-DEV is identified as affected. Upgrade the affected component to version abi-16.26; the referenced patch is 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68.
What is the impact of successful exploitation?
Successful exploitation causes an out-of-bounds read in the RTP Depacketizer. The supplied severity vector indicates low impacts to confidentiality, integrity, and availability.