Executive brief
GPAC MP4Box, a widely used tool for processing and packaging multimedia files, contains a flaw that can cause the application to crash. By providing a specially crafted MP4 file, an attacker can trigger a service failure, leading to a denial of service. This impact is primarily limited to the availability of the media processing workflow.
Technical details
A NULL pointer dereference vulnerability exists in GPAC MP4Box v2.4 within the gf_isom_get_user_data_count function located in isomedia/isom_read.c. The issue is triggered when the application attempts to read user data from a malformed MP4 file that lacks expected structures, leading to an unhandled null pointer access. An attacker can exploit this by providing a crafted file to be processed by the utility, resulting in an immediate crash (Denial of Service). This is a local attack vector requiring the victim to process the malicious file.
Affected products
- GPAC MP4Box 2.4
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory