The binary MP4Box in Gpac 1.0.1 has a double-free vulnerability in the avccomputepoc function in av_parsers.c, which allows attackers to cause a denial of service, even code execution and escalation of privileges.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:gpac:gpac:1.0.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "1.0.1"
},
{
"last_affected": "1.0.1"
}
],
"source": "CPE_STRING",
"vendor_product": "gpac:gpac"
}
]
}"2026-08-03T14:35:22Z"
[
{
"source": "https://github.com/gpac/gpac/commit/04dbf08bff4d61948bab80c3f9096ecc60c7f302",
"signature_type": "Function",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2021-40570-02f95021",
"digest": {
"function_hash": "39295482979318475893292998550012608033",
"length": 10192.0
},
"target": {
"file": "src/media_tools/av_parsers.c",
"function": "gf_avc_read_sps_bs_internal"
}
},
{
"source": "https://github.com/gpac/gpac/commit/04dbf08bff4d61948bab80c3f9096ecc60c7f302",
"signature_type": "Line",
"signature_version": "v1",
"deprecated": false,
"id": "CVE-2021-40570-e7a12def",
"digest": {
"threshold": 0.9,
"line_hashes": [
"162301846487824417085976151097850441387",
"290865607641083795548660822562839751511",
"36877859478553293821283680965112273961",
"277556399151842539648333058950472107336"
]
},
"target": {
"file": "src/media_tools/av_parsers.c"
}
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-40570.json"