CVE-2021-21848

medium
Published — · Modified —
CVSS v3
CVSS v2
VIR risk
5.5

Description

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. The library will actually reuse the parser for atoms with the “stsz” FOURCC code when parsing atoms that use the “stz2” FOURCC code and can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2021-21848

OS impact

OSVersionStatusFixed in
arch archaffected
debian debianbullseyefixed1.0.1+dfsg1-4+deb11u1

References

Verify integrity in audit chain (admin only). AS-IS.