CVE-2026-71614

GPAC · GPAC

A vulnerability in the GPAC media framework allows an attacker to execute arbitrary code via specially crafted inputs in the DVB MPE processing components.

Executive summary

A critical remote code execution vulnerability exists in the GPAC media framework that could allow a local attacker to compromise system integrity and availability.

Vulnerability

The vulnerability resides within the src/media_tools/dvb_mpe.c file, specifically affecting the descriptorTime_slice_fec_identifier and gf_m2ts_ipdatagram_reader functions. This flaw allows for arbitrary code execution, requiring no authentication from the attacker.

Business impact

The ability to execute arbitrary code on a system running GPAC poses a severe risk to organizational assets, potentially leading to full system compromise, data exfiltration, or denial of service. While the CVSS score of 8.4 reflects a high severity rating, the potential for total technical impact necessitates prioritized attention to secure affected environments.

Remediation

Immediate Action: Organizations should update to the version containing commit 0e4093392e1f847c90d20e031e893cd942fef938 or the latest stable release provided by the vendor.

Proactive Monitoring: Security teams should monitor system logs for abnormal process execution or crashes associated with media parsing tools.

Compensating Controls: Restrict the execution of media processing tools to isolated or sandboxed environments to limit the blast radius of a potential exploit.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the existence of a proof-of-concept, administrators should treat this vulnerability as a high priority for remediation. Apply the necessary updates as soon as they become available from the GPAC project to prevent potential exploitation of this memory-related flaw.

More GPAC CVEs

History

CVE Brief tracked this CVE 5 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 8.4 (3.1)
  4. Analyst report written

Sources