PT-2026-38628 · Gpac · Gpac
Lucian-2333
·
Published
2026-05-08
·
Updated
2026-05-10
·
CVE-2026-8124
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
GPAC versions prior to 26.02.0
Description
A flaw in the
sidx box read() function within the src/isomedia/box code base.c file allows for the allocation of resources through manipulation. This issue requires local access to be exploited.Recommendations
Install the patch identified as 442e2299530138d8f874fd885c565ba98a6318ba.
Exploit
Fix
Allocation of Resources Without Limits
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gpac