CVE-2025-55648: Heap-based Buffer Overflow in GPAC/MP4Box via gf_opus_parse_packet_header on crafted MP4 with corrupted stsz data
A heap buffer overflow in the gfopusparsepacketheader function (mediatools/avparsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
GPAC/MP4Boxfrom your environment.Uninstall MP4Box (GPAC MP4Box v2.4) from systems that do not require it to eliminate exposure to crafted MP4 files.
- Compensating control
Do not process untrusted or unverified MP4 files with MP4Box. If processing is required, isolate MP4Box parsing in a sandboxed environment or container, restrict network and filesystem access for the process, and apply file-acceptance controls (quarantine or block suspicious uploads).
- Operational
Monitor CVE-2025-55648 and vendor advisories for GPAC/MP4Box and apply any supplied security updates or patches as soon as they are released; until a vendor fix is available, remove or isolate MP4Box on systems exposed to untrusted MP4 files and re-evaluate previously processed files after patching.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55648?
CVE-2025-55648 has a medium severity rating of 5.5 according to the CVSS 3.1 scoring system.
How do I fix CVE-2025-55648?
To fix CVE-2025-55648, update to the latest version of GPAC MP4Box that addresses this heap-based buffer overflow vulnerability.
What types of attacks can CVE-2025-55648 enable?
CVE-2025-55648 can be exploited to cause a denial of service (DoS) through the use of crafted MP4 files with corrupted stsz data.
Which function is affected by CVE-2025-55648?
The gf_opus_parse_packet_header function in GPAC MP4Box is affected by the CVE-2025-55648 vulnerability.
What software is impacted by CVE-2025-55648?
CVE-2025-55648 impacts the GPAC MP4Box software, specifically version 2.4.