CVE-2021-30022
NixOS vulnerability analysis and mitigation

Overview

An integer overflow vulnerability was discovered in GPAC versions 0.5.2 to 1.0.1, identified as CVE-2021-30022. The vulnerability exists in the gfavcreadppsbsinternal function within the mediatools/av_parsers.c file. The issue was disclosed on April 19, 2021 (NVD).

Technical details

The vulnerability occurs when ppsid may be assigned a negative number, which bypasses the boundary check condition (ppsid >= 255). Since avc->pps array only has 255 units, this leads to a buffer overflow condition. Additionally, due to the assignment pps->id = pps_id, the vulnerability could potentially lead to an arbitrary address write (GitHub Issue).

Impact

Successful exploitation of this vulnerability could result in a system crash due to buffer overflow. Furthermore, due to the arbitrary address write capability, it could potentially lead to code execution in the context of the application (GitHub Issue).

Mitigation and workarounds

The vulnerability was patched in GPAC through commit 51cdb67ff7c5f1242ac58c5aa603ceaf1793b788, which added safety checks for avc/hevc/vvc sps/pps/vps ID verification. The fix includes additional validation to ensure pps_id is not negative before array access (GitHub Commit).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61619HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61618HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61617HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61610HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025
CVE-2025-61609HIGH7.5
  • NixOSNixOS
  • android
NoNoDec 01, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management