Junglewise Threat Intelligence

CVE-2025-55649: GPAC MP4Box NULL pointer dereference in gf_media_map_esd

CVE-2025-55649 · Severity: info · CVSS 5.5 · Published 2026-06-15

Technologies: Gpac MP4Box. Vendors: Gpac.

Executive brief

A vulnerability exists in GPAC MP4Box, a widely used tool for processing and packaging multimedia files. By tricking a user into opening a specially crafted MP4 file, an attacker can cause the application to crash unexpectedly. This results in a denial of service, potentially disrupting media production workflows or automated processing pipelines.

Technical details

A NULL pointer dereference vulnerability exists in GPAC MP4Box v2.4 within the gf_media_map_esd function located in media_tools/isom_tools.c. The flaw is triggered when the application attempts to process a malformed MP4 file containing specific Elementary Stream Descriptor (ESD) configurations that the parser fails to validate. An attacker can exploit this by providing a crafted media file to a user or an automated system using MP4Box, leading to an immediate application crash (Denial of Service). This is a local attack vector requiring the victim to interact with the malicious file.

Affected products

  • GPAC MP4Box 2.4

Timeline

  • 2026-06-15: disclosed: Initial disclosure of CVE-2025-55649

References

Related threats