CVE-2025-55649 Details
Description
A NULL pointer dereference in the gf_media_map_esd function (media_tools/isom_tools.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
A NULL pointer dereference vulnerability has been identified in GPAC MP4Box version 2.4 and earlier. The issue arises in the 'gf_media_map_esd' function within 'media_tools/isom_tools.c'. When the software processes a crafted MP4 file containing corrupted Elementary Stream Descriptor (ESD) data, the function fails to check if the 'URLString' pointer is NULL before using it. This oversight leads to a segmentation fault, causing a Denial of Service by crashing the application. The vulnerability can be exploited without any special privileges, simply by supplying a malicious MP4 file.
Users are advised to update to a version of GPAC that includes the fix for this vulnerability. The specific commit that addresses the issue is '10c16d54659b1b82dd49573dfeacfa9a5627a115', which is available in the GPAC GitHub repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/13/11 | CVE | ExploitMailing ListThird Party Advisory |
| https://infosec.exchange/@sigdevel/116736730620435563 | [email protected] | ExploitMitigationPatchThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-476 | NULL Pointer Dereference | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| gpac gpac | < 26.02.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 16, 2026 | Initial Analysis | [email protected] |
| Jun 15, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | CVE Modified | CVE |
| Jun 15, 2026 | New CVE Received | [email protected] |