OSV-2026-798

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/gpac/OSV-2026-798.yaml
JSON Data
https://api.test.osv.dev/v1/vulns/OSV-2026-798
Published
2026-05-22T00:20:52.141376Z
Modified
2026-05-23T14:45:05.257140956Z
Summary
Heap-use-after-free in ReplaceDEFNode
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=515134929

Crash type: Heap-use-after-free READ 8
Crash state:
ReplaceDEFNode
gf_sg_reset
gf_sg_del
References

Affected packages

OSS-Fuzz / gpac

Package

Name
gpac
Purl
pkg:generic/gpac

Affected ranges

Affected versions

abi-16.*
abi-16.12
abi-16.13
abi-16.14

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

introduced_range
"907fbb33591039a7d14492a9af3fac1baab2c5f6:b7607ad0e424919a4a30a97b5965d2b1703f50bd"
fixed_range
"0a81f305388687d8afa61da5cf000abf7b0b3bb8:4bf468922ac980cd35ce13eb36e02f2ec90f5142"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/gpac/OSV-2026-798.yaml"