Junglewise Threat Intelligence

CVE-2025-55645: GPAC MP4Box heap buffer overflow in gf_cenc_set_pssh

CVE-2025-55645 · Severity: info · Published 2026-06-15

Technologies: Gpac MP4Box. Vendors: Gpac.

Executive brief

GPAC MP4Box, a widely used tool for processing and packaging multimedia files, is vulnerable to a memory handling error. An attacker can exploit this by providing a specially crafted MP4 video file, which causes the application to crash. This results in a denial of service, potentially disrupting automated media processing workflows or individual user tasks.

Technical details

A heap buffer overflow vulnerability exists in GPAC MP4Box v2.4 within the gf_cenc_set_pssh function located in isomedia/drm_sample.c. The flaw is triggered when the application processes Common Encryption (CENC) Protection System Specific Header (PSSH) data in a malformed MP4 file. An attacker can exploit this by inducing a user or automated system to open a crafted file, leading to memory corruption and a subsequent application crash (Denial of Service). While the primary impact is DoS, heap overflows can sometimes be leveraged for further exploitation depending on the memory layout. No patch is explicitly detailed in the advisory, though users should exercise caution with untrusted media files.

Affected products

  • GPAC MP4Box 2.4

Timeline

  • 2026-06-15: disclosed: Initial publication of the CVE record.
  • 2026-06-15: advisory: NVD record published.

References

Related threats