CVE-2025-55639: NULL Pointer Defence in GPAC/MP4Box via gf_isom_add_track_kind on crafted MP4 file
Published Jun 23, 2026
·Updated
GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gfisomaddtrackkind() function at isomedia/isomwrite.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.
Affected Software
2 affected components
Gpac MP4Box=2.4
Gpac GPAC<26.02.0
Remediation
Patch Available
Event History
Jun 23, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55639?
CVE-2025-55639 has a medium severity score of 6.5 according to the CVSS 3.1 rating.
2
How do I fix CVE-2025-55639?
To fix CVE-2025-55639, apply the available patch from the GPAC repository.
3
What type of vulnerability is CVE-2025-55639?
CVE-2025-55639 is classified as a Null Pointer Dereference vulnerability.
4
What impact does CVE-2025-55639 have?
CVE-2025-55639 can lead to a Denial of Service (DoS) when a crafted MP4 file is processed.
5
Which software is affected by CVE-2025-55639?
CVE-2025-55639 affects GPAC MP4Box version 2.4.