OSV-2026-879

See a problem?
Import Source
https://github.com/google/oss-fuzz-vulns/blob/main/vulns/gpac/OSV-2026-879.yaml
JSON Data
https://api.osv.dev/v1/vulns/OSV-2026-879
Published
2026-06-08T00:02:29.284145Z
Modified
2026-06-11T14:37:17.340007Z
Summary
Heap-use-after-free in lsr_restore_base
Details

OSS-Fuzz report: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=520664955

Crash type: Heap-use-after-free READ 8
Crash state:
lsr_restore_base
lsr_read_polygon
lsr_read_scene_content_model
References

Affected packages

OSS-Fuzz / gpac

Package

Name
gpac
Purl
pkg:generic/gpac

Affected ranges

Affected versions

abi-16.*
abi-16.12
abi-16.13
abi-16.14
abi-16.15
abi-16.16
abi-16.17

Ecosystem specific

{
    "severity": "HIGH"
}

Database specific

fixed_range
"c2dee3aff638cd96f9617ac5b17dc2868cd90ef3:aa0fb77b82e51b159a2024c440cdf6b571b14d81"
source
"https://github.com/google/oss-fuzz-vulns/blob/main/vulns/gpac/OSV-2026-879.yaml"