CVE-2025-55651: NULL Pointer Defence in GPAC/MP4Box via gf_isom_get_user_data_count on truncated MP4 input
A NULL pointer dereference in the gfisomgetuserdatacount function (isomedia/isomread.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Do not process untrusted or unauthenticated MP4 files. Validate and sanitize MP4 input before supplying files to GPAC/MP4Box, since crafted or truncated MP4 files can trigger a NULL pointer dereference and cause Denial of Service.
- Compensating control
Run GPAC/MP4Box in an isolated, sandboxed environment with strict resource limits (CPU, memory, execution time) and least-privilege to contain the impact of a DoS triggered by a crafted MP4 file.
- Operational
Monitor GPAC/MP4Box processes for crashes, high resource usage, or service interruptions; log and investigate incidents involving truncated or malformed MP4 input and isolate affected instances.
- Operational
Apply any vendor-provided patch or upgrade to a fixed version as soon as a vendor release addressing CVE-2025-55651 becomes available.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55651?
CVE-2025-55651 has a medium severity rating with a CVSS score of 5.5.
How can I fix CVE-2025-55651?
To mitigate CVE-2025-55651, update to a patched version of GPAC MP4Box that addresses the NULL pointer dereference vulnerability.
What type of vulnerability is CVE-2025-55651?
CVE-2025-55651 is classified as a NULL pointer dereference vulnerability.
What impact does CVE-2025-55651 have?
CVE-2025-55651 can result in a Denial of Service (DoS) when exploited by supplying a crafted MP4 file.
Which software is affected by CVE-2025-55651?
The vulnerability CVE-2025-55651 affects GPAC MP4Box version 2.4.