Junglewise Threat Intelligence

CVE-2025-55639: GPAC MP4Box NULL pointer dereference in gf_isom_add_track_kind

CVE-2025-55639 · Severity: info · CVSS 5.5 · Published 2026-06-23

Technologies: Gpac MP4Box. Vendors: Gpac.

Executive brief

GPAC MP4Box, a popular tool for processing multimedia files, contains a vulnerability that can cause the application to crash. By tricking a user into opening a specially crafted MP4 file, an attacker can trigger a denial-of-service condition. This could disrupt workflows or automated systems that rely on MP4Box for media processing.

Technical details

A NULL pointer dereference exists in GPAC MP4Box v2.4 within the gf_isom_add_track_kind() function located in isomedia/isom_write.c. The vulnerability is triggered when the function attempts to process a 'kind' parameter using gf_strdup() without first verifying if the pointer is NULL, specifically when handling crafted MP4 files containing MPEG-H Audio tracks. An attacker can exploit this by providing a malicious MP4 file, leading to a segmentation fault and application crash (Denial of Service). A fix has been committed to the GPAC repository which adds a null guard before the string duplication call.

Affected products

  • GPAC MP4Box 2.4

Timeline

  • 2025-06-18: disclosed: Issue reported on GitHub
  • 2026-06-23: advisory: CVE published to NVD
  • 2025-06-18: patched: Fix committed to GPAC repository

References

Related threats