Sceawere

Vulnerability Detail

CVE-2026-108538UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Use-After-Free in GPAC gf_mx_v

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
4h ago
Vendor
n/a
Product
GPAC
Attack Type
Use After Free
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in GPAC up to 26.07.0. The impacted element is the function gf_mx_v of the file utils/os_thread.c of the component MP4Box. Such manipulation leads to use after free. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-10-11T05:16:53.477Z",
  "pubdate": "2026-10-11T05:16:53.477Z",
  "executiveSummary": "A critical Use-After-Free (UAF) vulnerability exists within the GPAC multimedia framework, specifically affecting the gf_mx_v function in utils/os_thread.c within the MP4Box component.\nThis vulnerability allows a remote attacker to trigger memory corruption, potentially leading to arbitrary code execution, denial-of-service, or unauthorized information disclosure.\nThe flaw affects all GPAC versions up to and including 26.07.0.\nAs the exploit has been publicly disclosed and the vendor has remained unresponsive, the risk is elevated due to the potential for weaponized exploitation by threat actors.\nThe vulnerability is remotely exploitable, meaning an attacker does not require local access or authentication to the host system to initiate the attack sequence, provided they can influence the input processed by the MP4Box component.",
  "technicalDetails": "The vulnerability originates in the memory management logic of the gf_mx_v function, located in the utils/os_thread.c file of the GPAC codebase. This function is responsible for mutex operations or thread synchronization primitives within the MP4Box utility. The defect manifests as a Use-After-Free (UAF) condition, where a pointer referencing a memory heap block remains active after the underlying memory has been deallocated or freed.\nExploitation of this vulnerability occurs when the application attempts to reference a memory object that has already been returned to the heap allocator. In a typical attack scenario, an adversary provides a crafted file or data stream to the MP4Box component. This malformed input triggers an error condition or specific execution path that invokes a 'free' operation on the target memory block, while a secondary thread or subsequent execution flow continues to attempt read or write operations on the dangling pointer.\nThe attack flow follows these phases: 1) Triggering the initial allocation of the vulnerable resource via MP4Box; 2) Influencing the application state to force an premature 'free' of the associated memory object; 3) Exploiting the persistence of the dangling pointer to perform a secondary operation (Write-After-Free or Read-After-Free). If the attacker is capable of heap spraying or manipulating the heap layout prior to the second reference, they can replace the original data with malicious payloads, effectively gaining control over function pointers or critical application data structures.\nBecause the vulnerability exists in the thread synchronization utility, the impact is exacerbated by the potential to disrupt process integrity in a multithreaded environment. Successful exploitation may lead to remote code execution (RCE) with the privileges of the user running the MP4Box binary. In environments where MP4Box is used as a backend for media processing services, this could result in full system compromise.\nThe technical requirement for exploitation is the ability to submit input that is processed by the GPAC engine. No authentication or elevated local privileges are strictly necessary for the initial triggering of the UAF condition, classifying this as a high-severity remote threat."
}
CVE-2026-108538: Use-After-Free in GPAC gf_mx_v (MEDIUM Severity, CVSS: 6.3) | Sceawere