Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in GPAC up to f1219cde. This affects the function gf_bt_report of the file scene_manager/loader_bt.c of the component MP4Box. The manipulation results in memory corruption. The attack may be performed from remote. The exploit has been made public and could be used. Upgrading to version abi-16.23 is able to mitigate this issue. The patch is identified as afca1f1181668d85941d51ed1adf647807d5d975. It is suggested to upgrade the affected component. | |
| Title | GPAC MP4Box loader_bt.c gf_bt_report memory corruption | |
| First Time appeared |
Gpac
Gpac gpac |
|
| Weaknesses | CWE-119 | |
| CPEs | cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gpac
Gpac gpac |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-14T05:30:13.562Z
Reserved: 2026-09-13T04:55:35.202Z
Link: CVE-2026-90686
No data.
Status : Received
Published: 2026-09-14T06:16:58.507
Modified: 2026-09-14T06:16:58.507
Link: CVE-2026-90686
No data.
OpenCVE Enrichment
Updated: 2026-09-14T06:30:12Z
-
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer