Executive brief
GPAC MP4Box, a popular tool for processing multimedia files, contains a vulnerability that can cause the application to crash. By tricking a user into opening a specially crafted MP4 file, an attacker can trigger a denial-of-service condition. This could disrupt workflows or automated systems that rely on MP4Box for media processing.
Technical details
A NULL pointer dereference exists in GPAC MP4Box v2.4 within the gf_isom_add_track_kind() function located in isomedia/isom_write.c. The vulnerability is triggered when the function attempts to process a 'kind' parameter using gf_strdup() without first verifying if the pointer is NULL, specifically when handling crafted MP4 files containing MPEG-H Audio tracks. An attacker can exploit this by providing a malicious MP4 file, leading to a segmentation fault and application crash (Denial of Service). A fix has been committed to the GPAC repository which adds a null guard before the string duplication call.
Affected products
- GPAC MP4Box 2.4
Timeline
- 2025-06-18: disclosed: Issue reported on GitHub
- 2026-06-23: advisory: CVE published to NVD
- 2025-06-18: patched: Fix committed to GPAC repository