Junglewise Threat Intelligence

CVE-2025-55658: GPAC MP4Box floating point exception in gf_opus_parse_packet_header

CVE-2025-55658 · Severity: info · CVSS 5.5 · Published 2026-06-09

Technologies: Gpac MP4Box. Vendors: Gpac.

Executive brief

GPAC MP4Box, a widely used multimedia packager and processor, is vulnerable to a crash when processing specifically malformed files. An attacker could provide a deceptive MP4 file to a user or automated system, causing the application to stop responding or shut down unexpectedly. This results in a denial of service, potentially disrupting media processing workflows or automated content pipelines.

Technical details

A floating point exception vulnerability exists in GPAC MP4Box v2.4 within the gf_opus_parse_packet_header function located in media_tools/av_parsers.c. The flaw is triggered when the parser encounters malformed Opus audio packet headers within an MP4 container. An attacker can exploit this by providing a specially crafted MP4 file to the utility. Successful exploitation leads to an immediate crash of the process (Denial of Service). This is a local attack vector requiring the victim to open or process the malicious file.

Affected products

  • GPAC MP4Box 2.4

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats