Junglewise Threat Intelligence

CVE-2025-55657: GPAC MP4Box NULL pointer dereference in gf_odf_vvc_cfg_write_bs

CVE-2025-55657 · Severity: info · Published 2026-06-09

Technologies: Gpac MP4Box. Vendors: Gpac.

Executive brief

A vulnerability in the GPAC MP4Box utility, a tool used for processing and packaging multimedia files, could allow an attacker to crash the application. By providing a specially crafted MP4 video file, an attacker can trigger a system error that stops the software from functioning. This primarily impacts the availability of media processing workflows that rely on this tool.

Technical details

A NULL pointer dereference vulnerability exists in GPAC MP4Box v2.4 within the gf_odf_vvc_cfg_write_bs function located in odf/descriptors.c. The issue is triggered when the application attempts to write VVC (Versatile Video Coding) configuration descriptors from a malformed MP4 file. An attacker can exploit this by supplying a specially crafted MP4 file that lacks expected data structures, leading to an application crash (Denial of Service). This is a local attack vector requiring the user or an automated system to process the malicious file. At the time of reporting, the vulnerability is identified in version 2.4.

Affected products

  • GPAC MP4Box 2.4

Timeline

  • 2026-06-09: disclosed: Initial disclosure and NVD publication

References

Related threats