There is a Null Pointer Dereference in function filtercore/filterpck.c:gffilterpcknewallocinternal in GPAC 1.0.1. The pid comes from function av1dmxparseflushsample, the ctx.opid maybe NULL. The result is a crash in gffilterpcknewalloc_internal.
[ { "signature_type": "Function", "id": "CVE-2021-30015-8c801ea3", "source": "https://github.com/gpac/gpac/commit/13dad7d5ef74ca2e6fe4010f5b03eb12e9bbe0ec", "signature_version": "v1", "target": { "function": "av1dmx_parse_flush_sample", "file": "src/filters/reframe_av1.c" }, "digest": { "function_hash": "58711868154071436767150960965126598198", "length": 938.0 }, "deprecated": false }, { "signature_type": "Line", "id": "CVE-2021-30015-aaf0fc37", "source": "https://github.com/gpac/gpac/commit/13dad7d5ef74ca2e6fe4010f5b03eb12e9bbe0ec", "signature_version": "v1", "target": { "file": "src/filters/reframe_av1.c" }, "digest": { "threshold": 0.9, "line_hashes": [ "165766728170830317054956550839990078013", "267444251905127156116583452213721798107", "303411012733722853373672359583694420871" ] }, "deprecated": false } ]