CVE-2022-36190
published 2022-08-17CVE-2022-36190: GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242.
PriorityP339critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.91%
55.8th percentile
GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | gpac | < gpac 1.0.1+dfsg1-4+deb11u2 (bullseye) | gpac 1.0.1+dfsg1-4+deb11u2 (bullseye) |
| gpac | gpac | < 2.2.0 | 2.2.0 |
| gpac | gpac | >= 0 < 1.0.1+dfsg1-4+deb11u2 | 1.0.1+dfsg1-4+deb11u2 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2022-36190: gpac - GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in func...
vendor_debian·2022·CVSS 9.8
CVE-2022-36190 [CRITICAL] CVE-2022-36190: gpac - GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in func...
GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242.
Scope: local
bullseye: resolved (fixed in 1.0.1+dfsg1-4+deb11u2)
VulDB
GPAC up to 2.1-DEV MP4Box gf_isom_dovi_config_get use after free (Issue 2220 / fef6242)
vuldb·2026-06-16·CVSS 9.8
CVE-2022-36190 [CRITICAL] GPAC up to 2.1-DEV MP4Box gf_isom_dovi_config_get use after free (Issue 2220 / fef6242)
A vulnerability described as critical has been identified in GPAC up to 2.1-DEV. This vulnerability affects the function gf_isom_dovi_config_get of the component MP4Box. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2022-36190. The attacker needs to be present on the local network. There is no available exploit.
It is best practice to apply a patch to resolve this issue.
GHSA
GHSA-h6jp-7q5x-g3xx: GPAC mp4box 2
ghsa_unreviewed·2022-08-18
CVE-2022-36190 [CRITICAL] CWE-416 GHSA-h6jp-7q5x-g3xx: GPAC mp4box 2
GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242.
OSV
CVE-2022-36190: GPAC mp4box 2
osv·2022-08-17·CVSS 9.8
CVE-2022-36190 [CRITICAL] CVE-2022-36190: GPAC mp4box 2
GPAC mp4box 2.1-DEV-revUNKNOWN-master has a use-after-free vulnerability in function gf_isom_dovi_config_get. This vulnerability was fixed in commit fef6242.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-08-17
Published