CVE-2026-1415

low
Published 2026-01-26 · Modified 2026-04-29
CVSS v3
3.3
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
CVSS v2
1.7
VIR risk
3.3

Description

A vulnerability was identified in GPAC up to 2.4.0. Affected is the function gf_media_export_webvtt_metadata of the file src/media_tools/media_export.c. The manipulation of the argument Name leads to null pointer dereference. The attack must be carried out locally. The exploit is publicly available and might be used. The identifier of the patch is af951b892dfbaaa38336ba2eba6d6a42c25810fd. To fix this issue, it is recommended to deploy a patch.

Predictions

Exploit likelihood
34%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-1415

vendor Authored 2026-05-27

Vendor advisory: cna@vuldb.com — https://github.com/gpac/gpac/issues/3428#issue-3802223345

vendor Authored 2026-05-27

Vendor advisory: cna@vuldb.com — https://github.com/gpac/gpac/issues/3428

vendor Authored 2026-05-27

Vendor advisory: cna@vuldb.com — https://github.com/enocknt/gpac/commit/af951b892dfbaaa38336ba2eba6d6a42c25810fd

OS impact

OSVersionStatusFixed in
debian debianbullseyeaffected

Application impact

VendorProductVersionsFixed
gpacgpac{"endIncluding":"2.4.0"}

References

CWEs

CWE-404 CWE-476

Verify integrity in audit chain (admin only). AS-IS.