CVE-2026-9572: GPAC MP4Box media.c Media_GetSample memory leak
A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function MediaGetSample of the file src/isomedia/media.c of the component MP4Box. Such manipulation of the argument cat leads to memory leak. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The name of the patch is e79c5cbe8b3fed27f4854ec229457d30c96206f1. It is best practice to apply a patch to resolve this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GPAC MP4Box (src/isomedia/media.c, Media_GetSample)to a version that resolves this vulnerability.Fixed in 2.4.0Patch e79c5cbe8b3fed27f4854ec229457d30c96206f1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-9572?
The severity of CVE-2026-9572 is classified as low with a score of 3.3.
What causes the CVE-2026-9572 vulnerability?
CVE-2026-9572 is caused by a memory leak in the Media_GetSample function of the MP4Box component in GPAC.
Who is affected by CVE-2026-9572?
CVE-2026-9572 affects users of GPAC versions up to 2.4.0.
How can I fix CVE-2026-9572?
To fix CVE-2026-9572, upgrade GPAC to the latest version that addresses the memory leak issue.
Can CVE-2026-9572 be exploited remotely?
CVE-2026-9572 can only be exploited from a local environment, not remotely.