CVE-2025-55647: Integer Overflow in GPAC/MP4Box via mp4_mux_cenc_insert_pssh on crafted MP4 with oversized PSSH metadata
An Out-of-Memory in the mp4muxcencinsertpssh function (filters/muxisom.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
GPAC MP4Boxfrom your environment.If MP4Box is not required, uninstall or remove GPAC MP4Box (v2.4) from systems until an official fix is available.
- Compensating control
Do not process untrusted or unauthenticated MP4 files containing PSSH metadata. If processing such files is necessary, run MP4Box in an isolated sandbox/container with strict resource limits (memory limits) and restrict or block sources that supply untrusted MP4 files to prevent Denial of Service from crafted files.
- Operational
Monitor systems that run MP4Box for crashes, out-of-memory conditions, or other DoS indicators when handling MP4 files; block or quarantine sources that trigger these conditions and escalate for investigation until a vendor patch is available.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55647?
CVE-2025-55647 has a medium severity rating of 5.5.
How do I fix CVE-2025-55647?
To mitigate CVE-2025-55647, update to the latest version of GPAC MP4Box that patches the integer overflow issue.
What type of vulnerability is CVE-2025-55647?
CVE-2025-55647 is classified as an integer overflow vulnerability that can lead to Denial of Service.
What impact does CVE-2025-55647 have on systems?
Exploitation of CVE-2025-55647 can cause an Out-of-Memory condition resulting in Denial of Service.
In which software is CVE-2025-55647 found?
CVE-2025-55647 affects GPAC MP4Box version 2.4.