PT-2026-52132 · Gpac+1 · Mp4Box+1
CVE-2025-60467
·
Published
2025-06-24
·
Updated
2026-07-07
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
GPAC Project/MP4Box versions prior to 26.02.0
Description
A use-after-free issue exists in the
gf filter pid inst swap delete task() function located in /filter core/filter pid.c. This flaw allows an attacker to trigger a Denial of Service (DoS) by providing a specially crafted media file. A use-after-free occurs when a program continues to use a pointer after it has been freed, which can lead to crashes or unpredictable behavior.Recommendations
Update to version 26.02.0 or later.
Exploit
Fix
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mp4Box
Red Os