Buffer Overflow Vulnerability in GPAC's MP4Box by GPAC Project
CVE-2025-60468

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 June 2026

What is CVE-2025-60468?

The GPAC Multimedia Open Source Project's MP4Box is susceptible to a buffer overflow vulnerability due to improper handling of freed objects during PID instance cleanup. Specifically, the function gf_filter_pid_inst_swap_delete_task() may trigger a heap use-after-free condition upon processing specially crafted MPEG-2 TS/MP4 files. Local, authenticated users can exploit this vulnerability during the filter teardown process, resulting in service crashes and potential denial of service. It is crucial for users to address this issue promptly to secure their systems from such exploitation.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.