PT-2026-22061 · Gpac · Gpac
Wooseokdotkim
·
Published
2026-02-26
·
Updated
2026-03-12
·
CVE-2026-27821
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
GPAC versions up to and including 26.02.0
Description
GPAC is an open-source multimedia framework. A stack buffer overflow occurs during NHML file parsing in
src/filters/dmx nhml.c. The xmlHeaderEnd XML attribute’s value from att->value is copied into the szXmlHeaderEnd buffer (size 1000 bytes) using the strcpy() function without length validation. If the input exceeds 1000 bytes, it overwrites the stack buffer boundary.Recommendations
Update to a version later than 26.02.0.
Exploit
Fix
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gpac