CVE-2026-93331 PUBLISHED

GPAC RTP Depacketizer rtp_depacketizer.c gf_rtp_parse_ttxt out-of-bounds

Assigner: VulDB
Reserved: 17.09.2026 Published: 18.09.2026 Updated: 18.09.2026

A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file src/ietf/rtp_depacketizer.c of the component RTP Depacketizer. Such manipulation of the argument size leads to out-of-bounds read. It is possible to launch the attack remotely. Upgrading to version abi-16.26 is able to resolve this issue. The name of the patch is 6bb0f64b4d1039c0fecd14ee2c1ee861d8661a68. The affected component should be upgraded.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 6.9

Product Status

Vendor n/a
Product GPAC
Versions
  • Version 26.08-DEV is affected
  • Version abi-16.26 is unaffected

Credits

  • dutch (VulDB User) reporter

References

Problem Types

  • Out-of-Bounds Read CWE
  • Memory Corruption CWE