CVE-2026-88339 Overview
CVE-2026-88339 is a NULL pointer dereference vulnerability [CWE-476] in the gf_sg_vrml_field_clone() function of GPAC version 2d7da22e (26.08-DEV). GPAC is an open-source multimedia framework used for packaging, streaming, and playing media content. The flaw occurs when the function clones a PROTO default SFImage field that has a NULL source pixel pointer. An attacker can supply a specially crafted input file that triggers the condition, causing the application to crash and resulting in denial of service.
Critical Impact
Local attackers can crash GPAC by delivering a malicious multimedia file, disrupting any workflow that processes untrusted VRML scene data.
Affected Products
- GPAC multimedia framework, commit 2d7da22e (version 26.08-DEV)
- Builds compiled from the affected src/scenegraph/vrml_tools.c source prior to patch commit c748219
- Downstream tools and applications embedding the vulnerable GPAC scenegraph library
Discovery Timeline
- 2026-09-22 - CVE-2026-88339 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-88339
Vulnerability Analysis
The defect resides in gf_sg_vrml_field_clone(), which copies VRML field data between scenegraph nodes. When cloning an SFImage field, the function computes an allocation size from the source image width, height, and numComponents values, then calls memcpy() from the source pixels buffer to a newly allocated destination buffer. The routine does not verify whether the source pixels pointer is NULL before dereferencing it. A PROTO default SFImage field can legitimately have a NULL pixel buffer, so cloning such a field triggers a NULL dereference and terminates the process. Because GPAC parses attacker-controlled media files, any tool linking the affected library is exposed to unexpected termination when handling malicious VRML input.
Root Cause
The root cause is missing input validation on the source pointer inside the GF_SG_VRML_SFIMAGE clone branch. The code assumes that a non-zero computed size implies a valid pixels buffer, but PROTO field defaults can hold uninitialized image data. Passing a NULL src argument to memcpy() produces undefined behavior and, in practice, a segmentation fault.
Attack Vector
Exploitation requires local access and user interaction: a victim must open or process a crafted file with a GPAC-based utility. Successful exploitation impacts availability only, with no confidentiality or integrity effects.
// Patch from src/scenegraph/vrml_tools.c (commit c748219)
((SFImage *)dest)->height = ((SFImage *)orig)->height;
((SFImage *)dest)->numComponents = ((SFImage *)orig)->numComponents;
size = ((SFImage *)dest)->width * ((SFImage *)dest)->height * ((SFImage *)dest)->numComponents;
- ((SFImage *)dest)->pixels = (u8*)gf_malloc(sizeof(char)*size);
- memcpy(((SFImage *)dest)->pixels, ((SFImage *)orig)->pixels, sizeof(char)*size);
+ if (((SFImage *)orig)->pixels && size > 0) {
+ ((SFImage *)dest)->pixels = (u8*)gf_malloc(sizeof(char)*size);
+ memcpy(((SFImage *)dest)->pixels, ((SFImage *)orig)->pixels, sizeof(char)*size);
+ } else {
+ ((SFImage *)dest)->pixels = NULL;
+ }
break;
case GF_SG_VRML_SFCOMMANDBUFFER:
Source: GitHub Commit c748219. The patch validates both the source pixels pointer and the computed size before allocating and copying, and assigns NULL to the destination pixels when either condition fails.
Detection Methods for CVE-2026-88339
Indicators of Compromise
- Unexpected termination of GPAC utilities such as MP4Box, MP4Client, or gpac while processing VRML or scene-description input files.
- Core dumps or crash reports referencing gf_sg_vrml_field_clone in libgpac.
- Presence of untrusted VRML, X3D, or BIFS files delivered through media pipelines, upload endpoints, or shared storage.
Detection Strategies
- Inventory hosts and containers running GPAC builds derived from commit 2d7da22e or the 26.08-DEV branch prior to c748219.
- Monitor application logs and operating system crash telemetry for repeated SIGSEGV signals in GPAC processes.
- Instrument media-processing pipelines with fuzz-tested input validators to reject malformed VRML PROTO structures before they reach GPAC.
Monitoring Recommendations
- Alert when GPAC processes exit abnormally within a short interval after ingesting a new file.
- Track file-hash reputation for VRML, X3D, and MP4 assets sourced from external users.
- Correlate crash events with the originating file path and submitting user to identify targeted denial-of-service attempts.
How to Mitigate CVE-2026-88339
Immediate Actions Required
- Rebuild GPAC from a source tree that includes commit c748219af5968fd70f6dc7ebe4d6dd9f495d4425 and redeploy affected binaries.
- Restrict who can submit VRML, X3D, and scene-description content to GPAC-based services.
- Isolate media conversion workloads in sandboxed or containerized environments so a crash does not affect other services.
Patch Information
The upstream fix is available in the commit titled "fuzz: fix null malloc in vrml sfimage alloc (closes #3855)" in src/scenegraph/vrml_tools.c. Details are tracked in GitHub Issue #3855 and GitHub Commit c748219. Downstream distributors should backport the change to any packaged 26.08-DEV builds.
Workarounds
- Disable processing of VRML and PROTO-bearing scene files until patched binaries are deployed.
- Add pre-processing validation that rejects SFImage fields lacking a valid pixel buffer.
- Run GPAC under a supervisor that automatically restarts the process and quarantines the offending input for review.
# Rebuild GPAC from a patched source tree
git clone https://github.com/gpac/gpac.git
cd gpac
git fetch origin
git checkout master # ensure commit c748219 or later is included
git log --oneline | grep c748219
./configure
make -j$(nproc)
sudo make install
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
