CVE-2025-55660: Stack-based Buffer Overflow in GPAC/MP4Box via gf_opus_ad_length on crafted MP4 file with malformed Opus packet
Published Jun 13, 2026
·Updated
A stack overflow in the gfopusreadlength function (mediatools/avparsers.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
Affected Software
2 affected components
Gpac MP4Box=2.4
Gpac GPAC<26.02.0
Remediation
Patch Available
Event History
Jun 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-55660?
CVE-2025-55660 has a medium severity rating of 5.5 based on the CVSS v3.1.
2
What does CVE-2025-55660 exploit?
CVE-2025-55660 exploits a stack-based buffer overflow in the gf_opus_read_length function of GPAC MP4Box when processing a crafted MP4 file.
3
How do I fix CVE-2025-55660?
To fix CVE-2025-55660, apply the available patch for GPAC MP4Box.
4
What type of attack can CVE-2025-55660 enable?
CVE-2025-55660 can allow attackers to cause a Denial of Service (DoS) by using a specially crafted MP4 file.
5
Which software is affected by CVE-2025-55660?
CVE-2025-55660 affects GPAC MP4Box version 2.4.