CVE-2026-71614
GPAC · GPAC
A vulnerability in the GPAC media framework allows an attacker to execute arbitrary code via specially crafted inputs in the DVB MPE processing components.
Executive summary
A critical remote code execution vulnerability exists in the GPAC media framework that could allow a local attacker to compromise system integrity and availability.
Vulnerability
The vulnerability resides within the src/media_tools/dvb_mpe.c file, specifically affecting the descriptorTime_slice_fec_identifier and gf_m2ts_ipdatagram_reader functions. This flaw allows for arbitrary code execution, requiring no authentication from the attacker.
Business impact
The ability to execute arbitrary code on a system running GPAC poses a severe risk to organizational assets, potentially leading to full system compromise, data exfiltration, or denial of service. While the CVSS score of 8.4 reflects a high severity rating, the potential for total technical impact necessitates prioritized attention to secure affected environments.
Remediation
Immediate Action: Organizations should update to the version containing commit 0e4093392e1f847c90d20e031e893cd942fef938 or the latest stable release provided by the vendor.
Proactive Monitoring: Security teams should monitor system logs for abnormal process execution or crashes associated with media parsing tools.
Compensating Controls: Restrict the execution of media processing tools to isolated or sandboxed environments to limit the blast radius of a potential exploit.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the high CVSS score and the existence of a proof-of-concept, administrators should treat this vulnerability as a high priority for remediation. Apply the necessary updates as soon as they become available from the GPAC project to prevent potential exploitation of this memory-related flaw.
More GPAC CVEs
History
CVE Brief tracked this CVE 5 days before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 8.4 (3.1)
- Analyst report written