Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-71616

CVE-2026-71616: GPAC Denial of Service Vulnerability

CVE-2026-71616 is a denial of service vulnerability in GPAC multimedia framework affecting the gf_route_media_complete_object function. Attackers can exploit this flaw to disrupt service availability. This article covers technical details, affected versions, impact analysis, and mitigation strategies.

Published:

CVE-2026-71616 Overview

CVE-2026-71616 is a denial of service vulnerability in GPAC, an open-source multimedia framework used for packaging, streaming, and playing digital media. The flaw resides in the gf_route_media_complete_object() function within the ROUTE (Real-time Object delivery over Unidirectional Transport) demultiplexer. An attacker can trigger the condition to disrupt processing of ROUTE-delivered media objects. The issue affects GPAC at commit c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 and was fixed in commit 3c4e6c5b3e0c6fa9b16d55599701a08354538fab.

Critical Impact

A remote attacker able to supply crafted ROUTE session input can cause GPAC to terminate or become unresponsive, disrupting media processing workflows.

Affected Products

  • GPAC multimedia framework at commit c2dee3aff638cd96f9617ac5b17dc2868cd90ef3
  • GPAC builds prior to fix commit 3c4e6c5b3e0c6fa9b16d55599701a08354538fab
  • Applications embedding the GPAC ROUTE demultiplexer (src/media_tools/route_dmx.c)

Discovery Timeline

  • 2026-09-09 - CVE-2026-71616 published to NVD
  • 2026-09-09 - Last updated in NVD database

Technical Details for CVE-2026-71616

Vulnerability Analysis

The vulnerability sits in gf_route_media_complete_object(), part of GPAC's ROUTE demultiplexer implementation in src/media_tools/route_dmx.c. The ROUTE protocol delivers file-based media objects over unidirectional networks and is used in ATSC 3.0 and DVB-I broadcast pipelines. The function participates in reassembling and finalizing transport objects identified by a Transport Session Identifier (TSI) and Transport Object Identifier (TOI).

The applied fix extends the internal service structure with additional TOI template metadata (toi_prefix and toi_suffix) rather than relying on a single toi_template string. This indicates the original implementation performed insufficient parsing or handling of the TOI template, allowing malformed or unexpected values to reach a code path that terminates execution or dereferences invalid state.

Root Cause

The root cause is improper handling of TOI template parsing within the ROUTE service descriptor. Without separate prefix and suffix fields, the demultiplexer could not correctly delimit template components when reconstructing media object identifiers, leading to a denial of service when processing crafted ROUTE traffic.

Attack Vector

An attacker delivers a crafted ROUTE session or LCT packet containing a malformed TOI template or object identifier. When GPAC processes the stream and invokes gf_route_media_complete_object(), the flawed parsing path causes the process to crash or hang. Exploitation requires the attacker to reach a GPAC instance consuming ROUTE input, such as a broadcast receiver or media processing service.

c
 typedef struct
 {
 	u32 tsi;
-	char *toi_template;
+	char *toi_template, *toi_prefix, *toi_suffix;
 	//for route services only, list of static files announced in STSID
 	GF_List *static_files;
 	u32 num_components;

Source: GPAC commit 3c4e6c5b3e0c6fa9b16d55599701a08354538fab

The patch splits the single toi_template field into a template plus explicit toi_prefix and toi_suffix components, giving the demultiplexer well-defined boundaries when matching TOI values.

Detection Methods for CVE-2026-71616

Indicators of Compromise

  • Unexpected termination or segmentation faults in GPAC processes (MP4Box, MP4Client, gpac) that consume ROUTE streams
  • Core dumps referencing gf_route_media_complete_object in route_dmx.c
  • Repeated restarts of media services ingesting ATSC 3.0 or DVB-I ROUTE traffic from untrusted sources

Detection Strategies

  • Inspect GPAC binaries and source builds to determine whether they include commit 3c4e6c5b3e0c6fa9b16d55599701a08354538fab or later
  • Enable core dump collection on hosts running GPAC-based receivers and review stack traces for the affected function
  • Monitor ROUTE ingestion services for abnormal termination rates coinciding with malformed LCT or STSID payloads

Monitoring Recommendations

  • Track process exit codes and crash telemetry for any binary linking against the GPAC libraries
  • Log and alert on GPAC restarts in production broadcast and streaming pipelines
  • Capture packet metadata for ROUTE sessions to enable retrospective analysis when a crash occurs

How to Mitigate CVE-2026-71616

Immediate Actions Required

  • Upgrade GPAC to a build that includes fix commit 3c4e6c5b3e0c6fa9b16d55599701a08354538fab
  • Rebuild any downstream applications that statically link against vulnerable GPAC libraries
  • Restrict exposure of GPAC ROUTE demultiplexers to trusted, authenticated network segments

Patch Information

The fix is available in the upstream GPAC repository. Review the GitHub commit update and the related GitHub issue discussion #3621 for details on the code change and reproduction context. Package maintainers should backport the commit to any distribution builds pinned to earlier revisions.

Workarounds

  • Disable ROUTE demultiplexer functionality in GPAC deployments that do not require ATSC 3.0 or DVB-I processing
  • Place network filters in front of GPAC receivers to drop ROUTE traffic from unauthorized sources
  • Run GPAC processes under a supervisor that restarts them automatically and isolates them with reduced privileges
bash
# Build GPAC from the patched source
git clone https://github.com/gpac/gpac.git
cd gpac
git checkout 3c4e6c5b3e0c6fa9b16d55599701a08354538fab
./configure
make -j$(nproc)
sudo make install

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.