No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 26 May 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 26 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box. The manipulation results in null pointer dereference. The attack needs to be approached locally. The exploit has been released to the public and may be used for attacks. The patch is identified as 525bf1af642c30af04e4df5345e6d798c0a4d8a1. It is advisable to implement a patch to correct this issue. | |
| Title | GPAC MP4Box isom_intern.c MergeFragment null pointer dereference | |
| First Time appeared |
Gpac
Gpac gpac |
|
| Weaknesses | CWE-404 CWE-476 |
|
| CPEs | cpe:2.3:a:gpac:gpac:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gpac
Gpac gpac |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-05-26T18:23:16.064Z
Reserved: 2026-05-26T10:52:27.927Z
Link: CVE-2026-9567
Updated: 2026-05-26T18:23:09.559Z
Status : Deferred
Published: 2026-05-26T18:16:58.883
Modified: 2026-05-26T19:37:00.120
Link: CVE-2026-9567
No data.
OpenCVE Enrichment
Updated: 2026-05-26T19:45:06Z