A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.
| Vendor | Product | Versions |
|---|---|---|
| gpac project | mp4box | n/a |
Updated description with more technical detail, changed severity to MEDIUM, and updated CVSS score to 4.3 with new CWE-416.
Updated vendor to GPAC, product to MP4Box, affected versions to 26.1.x, severity to CRITICAL, and marked exploit as available and actively exploited.
Initial creation