Sceawere
Vulnerability Detail
CVE-2026-108539UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
GPAC Use-After-Free in gf_fq_pop
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 4h ago
- Vendor
- n/a
- Product
- GPAC
- Attack Type
- Use After Free
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was detected in GPAC up to 26.07.0. This affects the function gf_fq_pop of the file filter_core/filter_queue.c of the component MP4Box. Performing a manipulation results in use after free. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-10-11T05:16:53.680Z",
"pubdate": "2026-10-11T05:16:53.680Z",
"executiveSummary": "A critical Use-After-Free (UAF) vulnerability exists within the GPAC multimedia framework, specifically affecting the MP4Box component. The flaw is located in the gf_fq_pop function within filter_core/filter_queue.c and impacts all versions up to and including 26.07.0.\nThis vulnerability stems from improper memory management during queue operations. An attacker can trigger this flaw remotely by providing a specifically crafted media file that manipulates the filter queue, leading to the use of memory that has already been deallocated.\nThe successful exploitation of this vulnerability can lead to arbitrary code execution, denial of service (application crash), or potential information disclosure. As the vulnerability is currently publicly disclosed and the vendor has remained unresponsive, the risk to systems utilizing GPAC for media processing is elevated. Exploitation does not require prior authentication, making it a viable target for remote attackers. Users and developers are advised to exercise caution when processing untrusted media content using affected versions of the MP4Box utility.",
"technicalDetails": "The vulnerability is rooted in the memory management logic of the gf_fq_pop function within filter_core/filter_queue.c. The function is responsible for removing an element from a filter queue; however, it fails to properly update references or synchronize memory access when handling specific queue states, resulting in a Use-After-Free condition.\nIn the context of MP4Box, the filter queue manages the orchestration of media processing tasks. An attacker can craft a malicious input file designed to trigger an edge case in the queue logic. During the processing of this file, the application invokes gf_fq_pop in a sequence that causes the function to access a memory pointer that was previously freed by the application's internal memory manager.\nThe attack flow initiates when the victim processes a malformed or malicious media file via MP4Box. The parser reaches the vulnerable code block while traversing the filter graph. By manipulating the queue structure through specific media metadata or stream headers, the attacker forces the application to release a resource while a pointer to that resource remains active in the processing pipeline. When the application subsequently attempts to read from or write to this dangling pointer, the UAF condition is satisfied.\nFrom an exploitation perspective, this primitive allows an attacker to achieve control over the program counter if they can groom the heap such that the freed memory is reallocated with attacker-controlled data. By placing a malicious payload in the heap location previously occupied by the queue node, the attacker can hijack execution flow when the program performs operations on the dangling pointer.\nThe affected component is the GPAC filter queue mechanism, which is integral to the MP4Box command-line tool. This vulnerability is reachable via remote input, meaning any network-facing service or automated processing pipeline that relies on GPAC to demux or transform media files is inherently susceptible. There are no known authentication requirements, as the vulnerability is triggered during the standard parsing and processing phase of media files. The post-exploitation impact ranges from local process termination, leading to service disruption, to potential full system compromise depending on the process's privilege context and available security mitigations like ASLR or DEP, which may be bypassed through sophisticated heap spraying techniques."
}