Wiz Agents & Workflows are here

CVE-2021-21853
NixOS vulnerability analysis and mitigation

Overview

Multiple exploitable integer overflow vulnerabilities exist within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. A specially crafted MPEG-4 input can cause an integer overflow due to unchecked addition arithmetic resulting in a heap-based buffer overflow that causes memory corruption. The vulnerability was discovered and reported by Cisco Talos team (Talos Blog, Talos Report).

Technical details

The vulnerability exists in the MPEG-4 decoding functionality where unchecked addition arithmetic operations can lead to integer overflows. When processing certain MPEG-4 atoms like 'name', 'rtp', and 'sdp', the library performs unsafe size calculations by truncating 64-bit sizes to 32-bit integers without proper validation. This truncation, combined with subsequent arithmetic operations, can result in integer overflows leading to undersized heap allocations and buffer overflows. The vulnerability has a CVSSv3 score of 8.8 (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) (Talos Report).

Impact

The vulnerability can lead to memory corruption through heap-based buffer overflows. An attacker who successfully exploits this vulnerability could potentially achieve code execution under the context of the library. The impact is significant as it affects the core MPEG-4 processing functionality of the library (Talos Report).

Mitigation and workarounds

Users are encouraged to update to GPAC Project Advanced Content commit a8a8d412dabcb129e695c3e7d861fcc81f608304 or later versions. For Debian users, the fix has been released in version 1.0.1+dfsg1-4+deb11u1 for the stable distribution (bullseye) (Debian Advisory).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-2370HIGH8.8
  • GitLabGitLab
  • gitlab
NoYesMar 30, 2026
CVE-2026-33206HIGH8.2
  • NixOSNixOS
  • calibre
NoYesMar 27, 2026
CVE-2026-33868MEDIUM6.1
  • NixOSNixOS
  • mastodon
NoYesMar 27, 2026
CVE-2026-33869MEDIUM4.8
  • NixOSNixOS
  • cpe:2.3:a:joinmastodon:mastodon
NoYesMar 27, 2026
CVE-2026-33205MEDIUM4.8
  • NixOSNixOS
  • cpe:2.3:a:calibre-ebook:calibre
NoYesMar 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management