CVE-2025-55664 Details
Description
A heap buffer overflow in the m2tsdmx_send_packet function (filters/dmx_m2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
A heap buffer overflow vulnerability has been identified in GPAC MP4Box version 2.5-DEV-rev1644-g8e3b5e1dd-master, specifically within the 'm2tsdmx_send_packet' function of the MPEG-2 Transport Stream demuxer. This vulnerability allows attackers to cause a denial-of-service condition by processing a crafted MP4 file that exploits the demuxer's failure to properly validate data sizes before memory copy operations. The issue arises when the demuxer encounters corrupted packet structures, which can lead to an invalidly large copy size being used, triggering the heap buffer overflow.
Users are advised to upgrade to the latest version of GPAC MP4Box that includes the fix for this vulnerability. The fix has been applied in the official GPAC repository. Instructions for downloading the latest version can be found on the GPAC GitHub page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 1, 2026CISA-ADP
Assessed Jun 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/06/01/10 | CVE | |
| https://github.com/gpac/gpac/commit/9bd6a72c9efc0513dfd33b87498afc7658dabd26 | [email protected] | Source CodeVendor |
| https://github.com/gpac/gpac/issues/3310 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://infosec.exchange/@sigdevel/116659245751279377 | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| GPAC MP4Box | 2.5-DEV-rev1644-g8e3b5e1dd-master |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | CVE Modified | CVE |
| Jun 1, 2026 | CVE Modified | CISA-ADP |
| Jun 1, 2026 | New CVE Received | [email protected] |
Volerion