Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in GPAC up to f1219cde. Affected by this vulnerability is the function stbl_GetSampleInfos of the file isomedia/stbl_read.c of the component MP4Box. The manipulation results in reachable assertion. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. Upgrading to version abi-16.23 addresses this issue. The patch is identified as 49dee5cad329cfed310c1682703df7daa47df31a. It is advisable to upgrade the affected component. | |
| Title | GPAC MP4Box stbl_read.c stbl_GetSampleInfos assertion | |
| First Time appeared |
Gpac
Gpac gpac |
|
| Weaknesses | CWE-617 | |
| CPEs | cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gpac
Gpac gpac |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-14T01:30:10.778Z
Reserved: 2026-09-12T19:39:24.362Z
Link: CVE-2026-90613
No data.
Status : Received
Published: 2026-09-14T02:17:15.690
Modified: 2026-09-14T02:17:15.690
Link: CVE-2026-90613
No data.
OpenCVE Enrichment
No data.
