CVE-2025-55644: Use-After-Fe in GPAC/MP4Box via gf_node_get_tag on crafted MP4 file with invalid BIFS GlobalQuantizer command
A heap use-after-free in the gfnodegettag function (scenegraph/basescenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
GPAC MP4Box v2.4from your environment.Uninstall or remove GPAC MP4Box v2.4 from affected systems or disable its use until a vendor-provided fix is available. Do not open untrusted or unverified MP4 files with this binary.
- Compensating control
Mitigate exposure by isolating or sandboxing any remaining MP4 processing (run MP4Box in a low-privilege container or restricted environment), and restrict ingestion of MP4 files from untrusted sources via network/file access controls.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55644?
CVE-2025-55644 is rated with a medium severity score of 5.5.
How does CVE-2025-55644 affect GPAC MP4Box?
CVE-2025-55644 allows attackers to cause a Denial of Service (DoS) by exploiting a heap use-after-free vulnerability in GPAC MP4Box.
What causes the vulnerability described in CVE-2025-55644?
The vulnerability occurs in the gf_node_get_tag function when processing crafted MP4 files containing an invalid BIFS GlobalQuantizer command.
Which version of GPAC MP4Box is affected by CVE-2025-55644?
CVE-2025-55644 affects GPAC MP4Box version 2.4.
How can I mitigate the risks associated with CVE-2025-55644?
Mitigating the risks of CVE-2025-55644 involves avoiding the use of crafted MP4 files and ensuring GPAC is updated to the latest version.