PT-2026-4721 · Gpac+1 · Gpac+1
Kery Qi
·
Published
2026-01-26
·
Updated
2026-02-16
·
CVE-2026-1418
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GPAC versions up to 2.4.0
Description
A security issue exists in GPAC related to the SRT Subtitle Import function. The
gf text import srt bifs function within the src/scene manager/text to bifs.c file is susceptible to an out-of-bounds write condition. This manipulation requires local access. The exploit has been publicly disclosed.Recommendations
Apply patch 10c73b82cf0e367383d091db38566a0e4fe71772.
Exploit
Fix
Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gpac
Red Os