CVE-2026-71614

Source
https://cve.org/CVERecord?id=CVE-2026-71614
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71614.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-71614
Downstream
Published
2026-09-09T00:00:00Z
Modified
2026-09-11T08:36:48Z
Summary
[none]
Details

An issue in GPAC c2dee3aff638cd96f9617ac5b17dc2868cd90ef3 allows an attacker to execute arbitrary code via the src/media_tools/dvb_mpe.c, descriptorTime_slice_fec_identifier() and gf_m2ts_ipdatagram_reader() components. Fixed in 0e4093392e1f847c90d20e031e893cd942fef938.

Database specific
{
    "cna_assigner": "mitre",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71614.json"
}
References

Affected packages

Git / github.com/gpac/gpac

Affected ranges

Type
GIT
Repo
https://github.com/gpac/gpac
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "REFERENCES"
}

Affected versions

Other
abi-12
abi-13
abi-14
abi-15
abi-16
abi-12.*
abi-12.16
abi-12.17
abi-12.18
abi-12.19
abi-12.20
abi-12.21
abi-12.22
abi-12.23
abi-12.24
abi-12.25
abi-12.26
abi-12.27
abi-13.*
abi-13.0
abi-14.*
abi-14.0
abi-15.*
abi-15.0
abi-15.1
abi-15.2
abi-16.*
abi-16.10
abi-16.11
abi-16.13
abi-16.14
abi-16.15
abi-16.16
abi-16.17
abi-16.2
abi-16.3
abi-16.4
abi-16.5
abi-16.6
abi-16.7
abi-16.8
abi-16.9
testtag0.*
testtag0.1
v0.*
v0.5.2
v0.6.0
v0.9.0
v0.9.0-preview
v1.*
v1.0.0
v2.*
v2.0.0
v2.2.0
v26.*
v26.02.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-71614.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "267706410807143064141978002223607207983",
            "length": 459
        },
        "id": "CVE-2026-71614-6540b33c",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/0e4093392e1f847c90d20e031e893cd942fef938",
        "target": {
            "file": "src/media_tools/dvb_mpe.c",
            "function": "section_DSMCC_INT"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "167017643536661699829221738725057711519",
                "144054689975404934488915024035987043517",
                "172657148292128730485288918898518369926",
                "244156923515677339642506525788691988611",
                "314380751998009485003967616943593461104",
                "90445792624362128146002515857461091506",
                "39193373138507607042461463172903422718",
                "172484741783456061641384657611619228333",
                "297831179737929201648992578973908679311",
                "220773563709789011740570946489692024168",
                "153014688867724933885178371295063296386",
                "132682575377384117832751033962344533539",
                "64136591346390095417914091130701281986",
                "47004666594839653183667557139632338800",
                "53432104267591167865671547986127967986",
                "46167685109119898891279214626630197344",
                "137381719325757547996820123992145482548",
                "327727531869132427374912629705621906002",
                "53432104267591167865671547986127967986",
                "299926588276209234146225627690532187852",
                "90304323904622563748244182843523403867",
                "232279644284414344008731126439487271335",
                "162525050577929410401227789291217677941",
                "232321513535769617273354327675297612457",
                "326449817801715496371257288975809132075",
                "198335599757882279591954842287731354720",
                "86727138208307416302224419390292933439",
                "320236542086197803407643748690393253844",
                "258078796308933500286893144199048022523",
                "17291034353084068571021420488734313283"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-71614-70610743",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/0e4093392e1f847c90d20e031e893cd942fef938",
        "target": {
            "file": "src/media_tools/dvb_mpe.c"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "291335029061353563176932692419617762419",
            "length": 433
        },
        "id": "CVE-2026-71614-9ce27611",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/0e4093392e1f847c90d20e031e893cd942fef938",
        "target": {
            "file": "src/media_tools/dvb_mpe.c",
            "function": "descriptorDSMCC_INT_UNT"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "20793328885506903346356681244401906633",
            "length": 363
        },
        "id": "CVE-2026-71614-9fb23a6a",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/0e4093392e1f847c90d20e031e893cd942fef938",
        "target": {
            "file": "src/media_tools/dvb_mpe.c",
            "function": "platform_descriptorDSMCC_INT_UNT"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "23358260541755395557523596504496630686",
            "length": 610
        },
        "id": "CVE-2026-71614-da103ae5",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/gpac/gpac/commit/0e4093392e1f847c90d20e031e893cd942fef938",
        "target": {
            "file": "src/media_tools/dvb_mpe.c",
            "function": "descriptorTime_slice_fec_identifier"
        }
    }
]
vanir_signatures_modified
"2026-09-11T08:36:48Z"