Summary

  • CVE: CVE-2026-TBD (CVE ID requested via MITRE, batch submission 2026-07-19)
  • Component: reframe_nalu.c (H.264/H.265 NALU reframer format probe)
  • Vulnerability Type: Heap buffer overflow (1-byte out-of-bounds read)
  • Vendor: GPAC
  • Product: GPAC (libgpac / MP4Box / gpac)
  • Affected Versions: master branch, commit 9bfcd13401cd1e52f966d03670c433d25952472c (26.03-DEV)
  • Fix Status: Fixed upstream: commit 03e5b1c (2026-07-22); issue #3742 closed 2026-07-23
  • Severity: Medium (5.5 / CVSS 3.1, 5.1 / CVSS 4.0): CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
  • Credit: Salim Largo (2ourc3)

Description

A heap-buffer-overflow (1-byte out-of-bounds read) exists in GPAC’s H.264/H.265 NALU reframer format probe: it reads data[1] without first checking that a second byte actually remains in the probe buffer.


Root cause

naludmx_probe_data (src/filters/reframe_nalu.c:4306):

if (data[0] & 0x40) { not_vvc++; continue; }
nal_type = data[1] >> 3;   // 4306: OOB read when only 1 byte remains

The probe walks NAL units across the buffer; when a single trailing byte remains, data[1] reads one byte past the end of the probe buffer, with no remaining-length check before the access.


Proof of Concept

afl-clang-fast -O1 -g -fsanitize=address -DGPAC_HAVE_CONFIG_H -I gpac_src -I gpac_src/include \
  harnesses/session_replay.c -L gpac_src/bin/gcc -lgpac -Wl,-rpath,gpac_src/bin/gcc -o session_replay
LD_LIBRARY_PATH=gpac_src/bin/gcc ./session_replay poc_file_heap_bof_read_naludmx_probe

Equivalent path: gf_fs_new(0, GF_FS_SCHEDULER_DIRECT, GF_FS_FLAG_NO_REGULATION) running inspect:deep:analyze=on:allp over the input registered as a gmem:// blob. The gpac / MP4Box CLI does not trigger this directly.

Observed ASan output (trimmed)

==98701==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x7c4bc21e00b3
READ of size 1 at 0x7c4bc21e00b3 thread T0
    #0 naludmx_probe_data src/filters/reframe_nalu.c:4306:14
    #1 gf_filter_pid_raw_new src/filter_core/filter.c:4801:13
    #2 gf_filter_pid_raw_gmem src/filter_core/filter.c:4880:6
    ...

0x7c4bc21e00b3 is located 0 bytes after 51-byte region

SUMMARY: AddressSanitizer: heap-buffer-overflow src/filters/reframe_nalu.c:4306:14 in naludmx_probe_data

Fix

Fixed upstream in commit 03e5b1c (2026-07-22), titled “fuzz: fix mem errors from filter setup_failure() and others”, a single patch that closed all ten vulnerabilities reported in this batch.

naludmx_probe_data() (src/filters/reframe_nalu.c) now guards the second-byte read with a remaining-length check:

nal_type = size > 1 ? data[1] >> 3 : 0;

Impact

Out-of-bounds heap read during format probing of untrusted H.264/H.265 input. Denial of service (crash).


Timeline

DateAction
2026-07-19Reported upstream (issue #3742)
2026-07-21Session-replay harness shared with maintainer on request
2026-07-22Fixed upstream, commit 03e5b1c
2026-07-23Issue closed

References