Summary

  • CVE: CVE-2026-TBD (CVE ID requested via MITRE, batch submission 2026-07-19)
  • Component: bitstream.c (core bitstream reader), reached via the AC-3 parser
  • Vulnerability Type: Heap buffer overflow (1-byte out-of-bounds read)
  • Vendor: GPAC
  • Product: GPAC (libgpac / MP4Box / gpac)
  • Affected Versions: master branch, commit 9bfcd13401cd1e52f966d03670c433d25952472c (26.03-DEV)
  • Fix Status: Fixed upstream: commit 03e5b1c (2026-07-22); issue #3740 closed 2026-07-23
  • Severity: Medium (5.5 / CVSS 3.1, 5.1 / CVSS 4.0): CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  • Credit: Salim Largo (2ourc3)

Description

A heap-buffer-overflow (1-byte out-of-bounds read) exists in GPAC’s core bitstream reader, reachable from the AC-3 audio parser: a bitstream declared larger than its backing allocation reads one byte past the end of that allocation.


Root cause

BS_ReadByte (src/utils/bitstream.c:460), reached via gf_bs_read_int ← gf_ac3_parser_bs (src/media_tools/av_parsers.c:10625):

if (bs->position >= bs->size) { ...; return 0; }
res = bs->original[bs->position++];   // 460: OOB read past the real allocation

The bounds check compares position against bs->size, but the AC-3 parse path builds a bitstream whose declared size exceeds the actually-allocated bs->original buffer. As a result, position < size passes the check while the byte read still lands past the real heap allocation.


Proof of Concept

afl-clang-fast -O1 -g -fsanitize=address -DGPAC_HAVE_CONFIG_H -I gpac_src -I gpac_src/include \
  harnesses/session_replay.c -L gpac_src/bin/gcc -lgpac -Wl,-rpath,gpac_src/bin/gcc -o session_replay
LD_LIBRARY_PATH=gpac_src/bin/gcc ./session_replay poc_file_heap_bof_read_bitstream_ac3

Equivalent path: gf_fs_new(0, GF_FS_SCHEDULER_DIRECT, GF_FS_FLAG_NO_REGULATION) running inspect:deep:analyze=on:allp over the input registered as a gmem:// blob. The gpac / MP4Box CLI does not trigger this directly.

Observed ASan output (trimmed)

==98712==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x7c9f7f7e0396
READ of size 1 at 0x7c9f7f7e0396 thread T0
    #0 BS_ReadByte src/utils/bitstream.c:460:9
    #1 gf_bs_read_bit src/utils/bitstream.c:540:17
    #2 gf_bs_read_int src/utils/bitstream.c:572:10
    #3 gf_bs_read_int_log_idx3 src/media_tools/av_parsers.c:47:12
    #4 gf_ac3_parser_bs src/media_tools/av_parsers.c:10625:12
    #5 gf_ac3_parser src/media_tools/av_parsers.c:10599:8
    #6 ac3dmx_probe_data src/filters/reframe_ac3.c:577:9
    ...

0x7c9f7f7e0396 is located 0 bytes after 790-byte region

SUMMARY: AddressSanitizer: heap-buffer-overflow src/utils/bitstream.c:460:9 in BS_ReadByte

Fix

Fixed upstream in commit 03e5b1c (2026-07-22), titled “fuzz: fix mem errors from filter setup_failure() and others”, a single patch that closed all ten vulnerabilities reported in this batch.

For this bug, src/media_tools/av_parsers.c was fixed in two places. First, gf_ac3_parser() now builds the bitstream with a size relative to the sync-code offset instead of the full original buffer length; this was the actual root cause, since it’s what let the declared size exceed the real remaining allocation:

bs = gf_bs_new((const char*)(buf + *pos), buflen-*pos, GF_BITSTREAM_READ);

Second, gf_ac3_parser_bs() gained an explicit length guard before reading the fixed-size AC-3 header fields:

if (gf_bs_available(bs) < 6) {
    GF_LOG(GF_LOG_WARNING, GF_LOG_CODING, ("[AC3] Truncated buffer\n"));
    return GF_FALSE;
}

Impact

Out-of-bounds heap read when parsing untrusted AC-3 audio streams. Denial of service (crash).


Timeline

DateAction
2026-07-19Reported upstream (issue #3740)
2026-07-21Session-replay harness shared with maintainer on request
2026-07-22Fixed upstream, commit 03e5b1c
2026-07-23Issue closed

References