Junglewise Threat Intelligence

CVE-2025-55651: GPAC MP4Box NULL pointer dereference in gf_isom_get_user_data_count

CVE-2025-55651 · Severity: info · Published 2026-06-09

Technologies: Gpac MP4Box. Vendors: Gpac.

Executive brief

GPAC MP4Box, a widely used tool for processing and packaging multimedia files, contains a flaw that can cause the application to crash. By providing a specially crafted MP4 file, an attacker can trigger a service failure, leading to a denial of service. This impact is primarily limited to the availability of the media processing workflow.

Technical details

A NULL pointer dereference vulnerability exists in GPAC MP4Box v2.4 within the gf_isom_get_user_data_count function located in isomedia/isom_read.c. The issue is triggered when the application attempts to read user data from a malformed MP4 file that lacks expected structures, leading to an unhandled null pointer access. An attacker can exploit this by providing a crafted file to be processed by the utility, resulting in an immediate crash (Denial of Service). This is a local attack vector requiring the victim to process the malicious file.

Affected products

  • GPAC MP4Box 2.4

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats