← console
voxell vciy

CVE-2021-21848

ROUTINE

Telemetry drift only. No threshold crossed and no authority ruling changed.

CVE record loaded 2026-09-20.

What to do now held facts and links

  1. No fix version is held. The CNA's first reference is the place to look: talosintelligence.com
  2. Record your decision, dated and frozen with today's evidence: patch by a date · mitigated by a compensating control · deferred · accepted the risk · not affected
  3. Check your version against the ranges this record publishes.

What it is stated by the CNA

An exploitable integer overflow vulnerability exists within the MPEG-4 decoding functionality of the GPAC Project on Advanced Content library v1.0.1. The library will actually reuse the parser for atoms with the “stsz” FOURCC code when parsing atoms that use the “stz2” FOURCC code and can cause an integer overflow due to unchecked arithmetic resulting in a heap-based buffer overflow that causes memory corruption. An attacker can convince a user to open a video to trigger this vulnerability.

weakness
CWE-680: Integer Overflow to Buffer Overflow
affected
n/a GPAC Project
versions
n/a GPAC Project GPAC Project Advanced Content commit a8a8d412dabcb129e695c3e7d861fcc81f608304,GPAC Project Advanced Content v1.0.1
published ranges
gpac 1.0.1; debian linux 10.0; debian linux 11.0
fixed in
No fix version in held sources.
severity
8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
assigned by
talos
published
2021-08-25

check us talosintelligence.com debian.org

Exploit code held, dated

exploit code
None held in the PoC-in-GitHub feed. A public repository changes this brief.

What moved held, dated

dateEPSSevent
26 Aug 20210.0034
1 Sep 20210.0051
6 Jan 20220.02249
4 Feb 20220.05246
7 Mar 20230.00121scoring model v2023.03.01
17 Mar 20250.00475scoring model v2025.03.14
18 Nov 20250.00561
21 Nov 20250.00245
15 Jun 20260.01577scoring model v2026.06.15
18 Jun 20260.01695

20 observations held. A step marked with a scoring model moved because the measurement was replaced, not because the vulnerability changed.

Outside the record researched, cited

This section reads the record's references and adds cited findings from outside it. It needs an account. Everything above is held facts and is complete without it.

Sign in to add the researched section

What would change this brief held, dated

CISA KEV
Not listed in the catalogue we hold. A listing changes this brief.
exploit probability
0.02 on 2026-06-18 (FIRST's EPSS, a probability and not evidence of exploitation). Next band line: 10% (0.10). Crossing a line changes this brief.
fix
No fix version is held. One published by the CNA or OSV changes this brief.

Watch this CVE What counts as a move

How to check this

Every value above is held with two dates: when it was true upstream (as_of) and when we recorded it (tx_from). Re-derive the exploit probability as it stood on any date:

SELECT value, source, source_version, as_of, tx_from
FROM volatile_valid_as_of('CVE-2021-21848', '2026-10-03T23:59:59.999999Z', now());

Identity above is quoted from the CVE Program record, corpus cvelistv5_20260920, recorded 30 Sep 2026.