Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-4015
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2026-4015 is a stack-based buffer overflow vulnerability in GPAC version 26.03-DEV, affecting the txtin_process_texml() function in src/filters/load_text.c within the TeXML File Parser component. The vulnerability was reported on February 22, 2026, by researcher BreakingBad6 via a GitHub issue, and was publicly disclosed on March 12, 2026. It affects GPAC 26.03-DEV (master HEAD) and has a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 base score of 4.8 (Medium) (VulDB via Feedly, GitHub Issue, Red Hat CVE).

Technical details

The root cause is an improper restriction of operations within the bounds of a memory buffer (CWE-119, CWE-121). In txtin_process_texml(), two fixed-size stack arrays are declared — GF_StyleRecord styles[50] and Marker marks[50] — with no bounds checking on the counters nb_styles and nb_marks. At line 3844, each parsed TeXML block writes to styles[nb_styles] via memset() without verifying that nb_styles < 50, and nb_styles++ is incremented unconditionally at line 3877; the same pattern exists for marks[nb_marks] near line 3970. An attacker can trigger the overflow by supplying a crafted TeXML file containing more than 50 style or marker blocks, processed locally via MP4Box (GitHub Issue, GitHub Commit). The attack vector is local and requires low privileges with no user interaction beyond processing the malicious file.

Impact

Successful exploitation can result in limited confidentiality, integrity, and availability impacts on the local system, as reflected in the CVSS scoring. The stack-based buffer overflow may cause application crashes (denial of service) or, under favorable conditions, enable arbitrary code execution in the context of the user running GPAC tools such as MP4Box. Because the attack is local and scoped to the affected process, lateral movement potential is low, but the vulnerability could be chained with other weaknesses in environments where GPAC processes untrusted media files automatically (GitHub Issue, Feedly).

Exploitability

A public proof-of-concept exploit is available: a Python script (poc_texml_overflow.py) and a crafted XML file (poc_texml_overflow.xml) were published alongside the GitHub issue report, generating a TeXML file with more than 60 style blocks to trigger the overflow (GitHub PoC, GitHub Issue). The CVSS v4.0 exploit maturity is rated as PROOF_OF_CONCEPT. The EPSS score is approximately 0.013% (0.000130), indicating a low probability of widespread exploitation. No in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported as of the latest available data (Feedly).

Exploitation steps

  1. Craft a malicious TeXML file: Use the public Python PoC (poc_texml_overflow.py) to generate a TeXML XML file containing more than 50 <style> blocks (e.g., 60 blocks), which exceeds the fixed stack array size of styles[50] in txtin_process_texml().
  2. Deliver the file to the target: Place the crafted poc_texml_overflow.xml on the local system where GPAC is installed, or in a directory processed automatically by a GPAC-based pipeline.
  3. Trigger processing via MP4Box: Execute the command MP4Box -add poc_texml_overflow.xml:ext=texml -new /tmp/test.mp4 to invoke the vulnerable TeXML parser.
  4. Overflow the stack buffer: As txtin_process_texml() iterates over the style blocks, it writes beyond the styles[50] array boundary via memset() without bounds checking, corrupting adjacent stack memory.
  5. Achieve impact: Depending on stack layout and memory protections, the overflow may crash the process (denial of service) or, in the absence of stack canaries or ASLR, potentially redirect execution flow for arbitrary code execution under the invoking user's privileges (GitHub Issue, GitHub PoC).

Indicators of compromise

  • Process: Unexpected crash or abnormal termination of MP4Box or gpac processes when processing TeXML files; ASAN/sanitizer output referencing txtin_process_texml in src/filters/load_text.c around line 3844.
  • File System: Presence of suspicious TeXML XML files with an unusually large number (>50) of <style> or <marker> blocks in directories processed by GPAC; presence of poc_texml_overflow.xml or similarly named files.
  • Logs: Core dump files generated by MP4Box or gpac; application logs showing [TXTLoad] Too many style blocks or [TXTLoad] Too many marker blocks warnings (only after patching); stack trace logs referencing load_text.c:3844 or load_text.c:3970.

Mitigation and workarounds

The GPAC project has released a patch in commit d29f6f1ada5cc284cdfa783b6f532c7d8bd049a5, which adds bounds checks before writing to styles[nb_styles] and marks[nb_marks], logging a warning and skipping excess blocks when the array limit is reached (GitHub Commit). Users should update to a build of GPAC that includes this commit (post-26.03-DEV master). As a workaround, avoid processing untrusted or externally sourced TeXML files with unpatched GPAC installations, and consider building GPAC with stack protection flags (-fstack-protector-strong) and ASLR enabled to reduce exploitation impact.

Community reactions

The vulnerability was reported through the GPAC GitHub issue tracker by researcher BreakingBad6 on February 22, 2026, and was promptly addressed by GPAC maintainer aureliendavid with a patch commit (GitHub Issue, GitHub Commit). The issue was also tracked by VulDB, ENISA's EUVD (EUVD-2026-11549), and Red Hat's CVE database. No significant broader media coverage or notable security researcher commentary beyond the initial disclosure has been identified.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Ubuntu

Unknown

bionic (esm-apps)

gpac

Unknown

focal (esm-apps)

gpac

Unknown

jammy

gpac

Unknown

jammy (esm-apps)

gpac

Unknown

noble

gpac

Unknown

noble (esm-apps)

gpac

Unknown

trusty (esm-infra-legacy)

gpac

Unknown

xenial (esm-apps-legacy)

gpac

Unknown

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93574MEDIUM6.5
  • Linux Debian logoLinux Debian
  • netty
NoNoSep 18, 2026
CVE-2026-93562MEDIUM6.5
  • Linux Debian logoLinux Debian
  • netty
NoNoSep 18, 2026
CVE-2026-93894LOW2.3
  • Linux Debian logoLinux Debian
  • varnish
NoNoSep 18, 2026
CVE-2026-82560NONEN/A
  • Linux Debian logoLinux Debian
  • perl
NoNoSep 19, 2026
CVE-2026-78030NONEN/A
  • Linux Debian logoLinux Debian
  • perl-DBI
NoYesSep 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management