NULL Pointer Dereference Vulnerability in GPAC MP4Box by GPAC
CVE-2025-55651

5.5MEDIUM

Key Information:

Vendor

GPAC

Vendor
CVE Published:
9 June 2026

What is CVE-2025-55651?

The GPAC MP4Box v2.4 contains a NULL pointer dereference vulnerability in the gf_isom_get_user_data_count function found in isomedia/isom_read.c. Attackers can exploit this vulnerability by supplying specially crafted MP4 files, potentially leading to a Denial of Service (DoS) condition. This flaw highlights the importance of robust file handling and input validation in media processing applications to prevent unexpected failures or system crashes.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.