CVE-2025-55660: Stack Overflow in GPAC MP4Box v2.4 Denial of Service
CVE-2025-55660 is a stack overflow vulnerability in GPAC's MP4Box tool version 2.4. When a user opens a specially crafted MP4 video file, the vulnerability triggers a crash that renders the application temporarily unusable. An attacker would need to trick a user into opening a malicious MP4 file; the vulnerability does not allow remote code execution or data theft, but causes a denial of service. This is a localized threat affecting anyone using MP4Box to process untrusted video files.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 5.5 MEDIUM · CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
- Weaknesses (CWE)
- CWE-121
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-15 / 2026-06-17
NVD description (verbatim)
A stack overflow in the gf_opus_read_length function (media_tools/av_parsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability exists in the gf_opus_read_length function within media_tools/av_parsers.c. This function is responsible for parsing Opus audio codec metadata from MP4 containers. A stack overflow occurs when the function reads a length field without proper bounds checking, allowing an attacker to write beyond the allocated stack buffer. The flaw is triggered during the parsing phase when MP4Box processes the file structure, specifically when encountering a crafted Opus metadata block with an oversized length value. The stack corruption leads to application termination via segmentation fault or stack canary protection.
Business impact
For organizations and professionals using MP4Box as part of media processing pipelines, this vulnerability introduces operational risk. If MP4Box is integrated into automated workflows—such as video transcoding services, broadcast systems, or media asset management platforms—a malicious MP4 file can crash the process and disrupt service availability. The impact is primarily availability-focused; there is no confidentiality or integrity breach. However, if the tool runs with elevated privileges or in a shared environment, repeated crashes could be weaponized as a nuisance attack or part of a larger supply-chain scenario involving compromised video feeds.
Affected systems
GPAC MP4Box v2.4 is affected. Organizations should determine whether they deploy this specific version and the context in which it is used. The vulnerability is triggered only when processing MP4 files, so the risk is confined to systems that ingest or validate video content. Both command-line usage and any application embedding the affected GPAC library are in scope.
Exploitability
Exploitation requires user interaction: an attacker must craft a malicious MP4 file and convince a user to open it with MP4Box. There is no network attack surface; the vulnerability is local. The CVSS score of 5.5 (MEDIUM severity) reflects this limitation. The attack is not complex and does not require special privileges, but the necessity for user action limits real-world risk. The vulnerability does not appear on CISA's Known Exploited Vulnerabilities (KEV) list, indicating no active in-the-wild exploitation has been disclosed or observed as of the advisory date.
Remediation
Users should update GPAC to a patched version released after June 17, 2026. Consult the official GPAC release notes and security advisories to identify the minimum patched version. In the interim, restrict MP4Box usage to trusted, validated video sources and disable automated processing of untrusted MP4 files. If feasible, run MP4Box in a sandboxed or containerized environment to limit the blast radius of a crash.
Patch guidance
Check the official GPAC project repository and release page for version updates following the June 2026 disclosure. A patch is expected to be released; verify against the vendor advisory before deploying. Update procedures depend on your deployment model: if MP4Box is installed standalone, upgrade via package manager or direct download; if embedded in an application, await an updated vendor release. Test the patch in a non-production environment before rolling out to production pipelines.
Detection guidance
Monitor for unexpected crashes or restarts of MP4Box processes, particularly when processing files from external or untrusted sources. Log and review any segmentation faults or stack buffer overrun exceptions in MP4Box logs. If security monitoring is in place, flag attempts to process MP4 files with suspicious or unusual metadata structures. Network-based detection is not applicable since the attack is file-local, but endpoint monitoring for abnormal process termination of media tools can help identify exploitation attempts.
Why prioritize this
This vulnerability merits medium priority based on its CVSS score and operational context. While the impact is limited to denial of service and user interaction is required, the widespread use of MP4Box in media processing and the potential for automated exploitation in batch workflows elevate its importance. Organizations with MP4 processing pipelines should prioritize patching, especially those handling untrusted video content. Non-critical systems with minimal user interaction can be addressed in routine maintenance windows, whereas mission-critical media services should patch sooner.
Risk score, explained
The CVSS 3.1 score of 5.5 (MEDIUM) is derived from the attack vector being local (AV:L), low attack complexity (AC:L), no privileges required (PR:N), and user interaction necessary (UI:R). The impact is high availability loss (A:H) with no confidentiality or integrity impact. This profile reflects a realistic threat that is exploitable but requires deliberate social engineering or supply-chain compromise to trigger in practice.
Frequently asked questions
Can this vulnerability be exploited remotely over the network?
No. The vulnerability requires local file access and user interaction. An attacker must trick a user into opening a malicious MP4 file on their system with MP4Box. Remote exploitation is not possible.
Will patching MP4Box prevent all MP4-related crashes?
No. This patch addresses only the stack overflow in gf_opus_read_length. Other parsing bugs or edge cases may exist in MP4Box. The patch mitigates this specific vulnerability; comprehensive testing of your media pipelines is still recommended.
Do we need to patch if we only process MP4 files from internal trusted sources?
If your organization strictly controls all MP4 input and verifies file integrity before processing, your immediate risk is lower. However, patching is still recommended as a defense-in-depth measure, especially if operational procedures change or new team members are onboarded.
Is this vulnerability exploitable via a malicious MP4 embedded in a web page?
No direct web exploitation is feasible. However, if a user downloads the MP4 and opens it in MP4Box, the vulnerability can be triggered. Delivery via email or file-sharing services remains the most plausible attack vector.
This analysis is based on information available as of June 17, 2026. Patch version numbers and remediation timelines should be verified against official GPAC project releases and security advisories. No guarantee is provided regarding the completeness or future evolution of this vulnerability's impact or exploitability. Organizations should conduct their own risk assessment based on their specific deployment and threat model. SEC.co does not provide legal, compliance, or business continuity advice; consult your internal security and business teams before taking action. Source: NVD (public-domain), retrieved 2026-07-23. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2025-52292HIGHGPAC MP4Box Stack Buffer Overflow Denial of Service
- CVE-2025-59613MEDIUMQualcomm Memory Corruption Vulnerability – Firmware Security Impact
- CVE-2025-62858MEDIUMQNAP Buffer Overflow (QTS / QuTS hero) – Patch Now
- CVE-2025-7019MEDIUMAvast Norton AVG Antivirus Stack Overflow DoS (Definition Update Required)
- CVE-2026-0413MEDIUMNETGEAR Orbi Buffer Overflow Firmware Vulnerability
- CVE-2026-10064MEDIUMTRENDnet TEW-432BRP Stack Overflow – Unpatched EOL Router Vulnerability
- CVE-2026-11793MEDIUM389 Directory Server Stack Buffer Overflow in Password Parsing
- CVE-2026-1871MEDIUMTP-Link Tapo C200 v5 RTSP Buffer Overflow DoS Vulnerability