CVE-2026-90612 PUBLISHED

GPAC MP4Box scene_dump.c gf_sm_dump_command_list assertion

Assigner: VulDB
Reserved: 12.09.2026 Published: 14.09.2026 Updated: 14.09.2026

A vulnerability was identified in GPAC up to f1219cde. Affected is the function gf_sm_dump_command_list of the file scene_manager/scene_dump.c of the component MP4Box. The manipulation leads to reachable assertion. The attack must be carried out locally. The exploit is publicly available and might be used. Upgrading to version abi-16.23 is able to address this issue. The identifier of the patch is afca1f1181668d85941d51ed1adf647807d5d975. Upgrading the affected component is advised.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 4.8

Product Status

Vendor n/a
Product GPAC
Versions
  • Version f1219cde is affected
  • Version abi-16.23 is unaffected

Credits

  • r1ck9 (VulDB User) reporter

References

Problem Types

  • Reachable Assertion CWE