CVE-2026-4185

A vulnerability was found in GPAC up to 2.5-DEV-rev2167-gcc9d617c0-master. This vulnerability affects the function swf_def_bits_jpeg of the file src/scene_manager/swf_parse.c of the component MP4Box. The manipulation of the argument szName results in stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been made public and could be used. The patch is identified as 8961c74f87ae3fe2d3352e622f7730ca96d50cf1. A patch should be applied to remediate this issue.
Configurations

No configuration.

History

22 Apr 2026, 21:32

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad fue encontrada en GPAC hasta 2.5-DEV-rev2167-gcc9d617c0-master. Esta vulnerabilidad afecta a la función swf_def_bits_jpeg del archivo src/scene_manager/swf_parse.c del componente MP4Box. La manipulación del argumento szName resulta en desbordamiento de búfer basado en pila. Es posible lanzar el ataque remotamente. El exploit ha sido hecho público y podría ser usado. El parche se identifica como 8961c74f87ae3fe2d3352e622f7730ca96d50cf1. Un parche debería aplicarse para remediar este problema.

16 Mar 2026, 14:19

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 14:19

Updated : 2026-04-29 01:00


NVD link : CVE-2026-4185

Mitre link : CVE-2026-4185

CVE.ORG link : CVE-2026-4185


JSON object : View

Products Affected

No product.

CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow