Junglewise Threat Intelligence

CVE-2025-60481: GPAC MP4Box NULL pointer dereference in gf_odf_ac4_cfg_dsi_v1

CVE-2025-60481 · Severity: info · CVSS 5.5 · Published 2026-06-01

Vendors: Gpac.

Executive brief

GPAC MP4Box, a widely used tool for processing multimedia files, is vulnerable to a crash when handling specifically malformed AC4 audio files. An attacker could provide a deceptive audio file to a user, which, when processed, causes the application to shut down unexpectedly. This results in a denial-of-service, potentially disrupting automated media processing workflows or individual user tasks.

Technical details

A NULL pointer dereference exists in the gf_odf_ac4_cfg_dsi_v1 function within odf/descriptors.c of GPAC Project/MP4Box. The vulnerability is triggered when the application fails to validate pointers before accessing AC4 descriptor substructures during the parsing of invalid or specially crafted AC4 configurations. An attacker can exploit this by supplying a malicious AC4 file, leading to a segmentation fault and application crash (Denial of Service). The issue was identified via AddressSanitizer and has been addressed in the GPAC repository.

Affected products

  • GPAC GPAC Project/MP4Box before 26.02.0

Timeline

  • 2025-07-14: disclosed: Issue reported on GitHub
  • 2025-07-15: patched: Fix committed to GPAC repository
  • 2026-06-01: advisory: CVE published to NVD

References