PT-2026-43373 · Mp4Box+1 · Mp4Box+1

·

CVE-2026-9567

·

Published

2026-05-26

·

Updated

2026-05-26

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GPAC versions prior to 2.4.1
Description A security flaw in the MP4Box component allows for a null pointer dereference, which occurs when the MergeFragment() function in the src/isomedia/isom intern.c file is manipulated. This issue requires local access to be exploited.
Recommendations Apply patch 525bf1af642c30af04e4df5345e6d798c0a4d8a1 to resolve the issue. As a temporary workaround, restrict access to the MergeFragment() function within the MP4Box component to minimize the risk of exploitation.

Exploit

Fix

NULL Pointer Dereference

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09998
CVE-2026-9567

Affected Products

Gpac
Mp4Box