Junglewise Threat Intelligence

CVE-2025-52293: GPAC MP4Box segmentation violation in gf_hevc_read_sps_bs_internal

CVE-2025-52293 · Severity: info · Published 2026-06-09

Technologies: Gpac MP4Box. Vendors: Gpac.

Executive brief

A vulnerability in GPAC MP4Box, a popular tool for processing multimedia files, can cause the application to crash when handling specifically modified video data. An attacker could provide a malicious video file to a user or automated system, leading to a denial-of-service where the software stops functioning. This primarily impacts the reliability of media processing workflows and automated video conversion services.

Technical details

A segmentation violation exists in GPAC MP4Box v2.4 within the gf_hevc_read_sps_bs_internal function located in media_tools/av_parsers.c. The issue is triggered during the parsing of High Efficiency Video Coding (HEVC) Sequence Parameter Set (SPS) data. By providing a specially crafted media file containing malformed SPS headers, a local attacker can cause a null pointer dereference or out-of-bounds memory access, resulting in an immediate application crash (Denial of Service). This vulnerability is typically exploited when the utility is used to inspect or process untrusted video files.

Affected products

  • GPAC MP4Box 2.4

Timeline

  • 2026-06-09: disclosed: Initial disclosure of CVE-2025-52293

References

Related threats