PT-2026-44037 · Gpac · Mp4Box

CVE-2025-70116

·

Published

2026-05-27

·

Updated

2026-05-30

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions GPAC MP4Box (affected versions not specified)
Description A NULL pointer dereference occurs when parsing certain truncated MP4 files. An unknown or invalid stsd entry can lead to missing descriptor fields, such as codec, mime, or profile strings. Consequently, the gf media map esd() function calls strlen() on a NULL pointer, resulting in a crash.

Exploit

Fix

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-70116

Affected Products

Mp4Box