Executive brief
A vulnerability in the MP4Box utility, a tool used for processing and packaging multimedia files, could allow an attacker to crash the application. By tricking a user into processing a specially crafted MPEG-2 video file, an attacker can cause a service disruption. This impact is limited to the availability of the tool during the processing of the malicious file.
Technical details
A heap use-after-free vulnerability exists in the dasher_process function within /filters/dasher.c of GPAC Project/MP4Box. The issue occurs when processing crafted MPEG-2 Transport Stream (TS) files containing corrupted Program Map Table (PMT) descriptors and repeated sync marker violations. Specifically, the dasher module fails to properly manage PID context memory; after a PID context is freed in dasher_configure_pid(), a stale pointer is subsequently accessed in dasher_process(). An attacker can exploit this by providing a malicious MPEG-2 file, leading to an application crash (Denial of Service). The vulnerability is addressed in version 26.02.0.
Affected products
- GPAC GPAC Project/MP4Box before 26.02.0
Timeline
- 2026-06-01: advisory: NVD publication date
- 2026-06-01: disclosed