CVE-2025-55650: Use-After-Fe in GPAC/MP4Box via gf_svg_node_del on crafted MP4 file processed with -svg
A heap use-after-free in the gfnodegettag function (scenegraph/basescenegraph.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
GPAC MP4Box v2.4from your environment.Uninstall or avoid using GPAC MP4Box v2.4 until the vendor releases a security fix.
- Configuration
Do not process untrusted MP4 files using MP4Box's -svg option; disable or avoid using the -svg feature until an official patch is available.
GPAC MP4Box svg processing (-svg) = disabled / avoid using -svg - Compensating control
Process MP4 files in an isolated/sandboxed environment and restrict processing to trusted inputs. Block or quarantine uploads of untrusted MP4 files before they are processed by MP4Box.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55650?
The severity of CVE-2025-55650 is rated as medium with a score of 5.5.
What is the impact of CVE-2025-55650?
CVE-2025-55650 can lead to a Denial of Service (DoS) condition when a crafted MP4 file is processed.
How can I fix CVE-2025-55650?
To fix CVE-2025-55650, upgrade to a patched version of GPAC MP4Box that addresses this vulnerability.
What does CVE-2025-55650 exploit?
CVE-2025-55650 exploits a heap use-after-free vulnerability in the gf_node_get_tag function.
Is CVE-2025-55650 specific to certain software?
Yes, CVE-2025-55650 specifically affects GPAC MP4Box version 2.4.