<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3agpacgpac/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 15 Sep 2026 07:39:39 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3agpacgpac/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Use-After-Free Vulnerability in GPAC Compositor</title><link>https://feed.craftedsignal.io/briefs/2026-09-gpac-uaf/</link><pubDate>Tue, 15 Sep 2026 07:39:39 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-gpac-uaf/</guid><description>A use-after-free vulnerability in the GPAC compositor component (CVE-2026-91087) allows remote attackers to trigger memory corruption via malicious media files.</description><content:encoded><![CDATA[<p>A use-after-free vulnerability has been identified in the GPAC multimedia framework, specifically affecting the 'gf_mo_get_od_id' function within 'compositor/media_object.c'. The flaw exists in all versions up to f1219cde. This vulnerability allows for remote exploitation when a user processes a specifically crafted malicious media file. Successful exploitation leads to memory corruption, which may result in application crashes or the potential for arbitrary code execution. As public exploit code for this vulnerability is currently available, it poses a significant risk to systems processing untrusted media content. The issue is addressed in the GPAC project by upgrading to version 'abi-16.24' or applying the patch identified by commit 'e34f4ba349d55cd1849f0bcf4cf46552732e2db7'. Organizations using GPAC as a library or standalone tool should prioritize patching.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability is rated with a CVSS v3.1 base score of 7.3, reflecting its high impact and remote exploitability. Successful exploitation allows for unauthorized memory access, potentially leading to service disruption through crashes or exploitation as an entry point for remote code execution. This impacts any environment utilizing GPAC to parse or render multimedia content, such as media players, streaming servers, or content transcoding pipelines.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of GPAC to version 'abi-16.24' or later.</li>
<li>If upgrading is not immediately feasible, apply patch 'e34f4ba349d55cd1849f0bcf4cf46552732e2db7' to the 'compositor/media_object.c' source file.</li>
<li>Monitor file processing services that ingest external media for unexpected process crashes or anomalous memory usage.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>memory-corruption</category><category>remote-code-execution</category><category>cve</category></item></channel></rss>