CVE-2025-55648 Details
Description
A heap buffer overflow in the gf_opus_parse_packet_header function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
A heap buffer overflow vulnerability has been identified in GPAC MP4Box version 2.4 and prior. The issue arises in the 'gf_opus_parse_packet_header' function within 'media_tools/av_parsers.c'. When MP4Box processes a crafted MP4 file containing corrupted sample-size data for an Opus track, the parser fails to properly validate the input buffer length before interpreting the Opus packet header. This oversight allows attackers to read beyond the allocated memory, leading to a crash and potential memory corruption.
Users are advised to update to a version of GPAC that includes the fix for this vulnerability. The fix has been applied in the commit 'cea49f684dbc4d53ecd6c76a9623838802a68d88'.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/13/10 | CVE | ExploitMailing ListThird Party Advisory |
| https://infosec.exchange/@sigdevel/116736751244916557 | [email protected] | ExploitMitigationPatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| gpac gpac | < 26.02.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 15, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | CVE Modified | CVE |
| Jun 15, 2026 | New CVE Received | [email protected] |