Vulnerability Description
GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Gpac | Gpac | < 26.02.0 |
Related Weaknesses (CWE)
References
- https://github.com/gpac/gpac/commit/027ce139dda498ee95df36db9f9f6f3cadce8ec9Patch
- https://github.com/gpac/gpac/issues/3260ExploitIssue Tracking
- https://github.com/sigdevel/pocs/blob/main/res/gpac/MP4Box/23/23_poc.mp4Exploit
- https://infosec.exchange/@sigdevel/116769184815236865ExploitPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2026/06/26/2ExploitMailing ListThird Party Advisory
- https://github.com/gpac/gpac/issues/3260ExploitIssue Tracking
FAQ
What is CVE-2025-55639?
CVE-2025-55639 is a vulnerability with a CVSS score of 6.5 (MEDIUM). GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Servic...
How severe is CVE-2025-55639?
CVE-2025-55639 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-55639?
Check the references section above for vendor advisories and patch information. Affected products include: Gpac Gpac.