CVE-2025-55664: Heap-based Buffer Overflow in GPAC/MP4Box via m2tsdmx_send_packet on crafted MPEG-2 TS file

Published Jun 1, 2026
·
Updated

A heap buffer overflow in the m2tsdmxsendpacket function (filters/dmxm2ts.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.

Affected Software

1 affected component
Gpac MP4Box=2.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove GPAC MP4Box v2.4 from your environment.

    Uninstall GPAC MP4Box v2.4 from any systems where it is not required to eliminate exposure to the heap buffer overflow in m2tsdmx_send_packet.

  2. Compensating control

    Do not process untrusted MP4 or MPEG-2 TS files with MP4Box. If processing is required, perform it in a sandboxed or isolated environment with least privileges, and validate/scan input files before feeding them to MP4Box to reduce risk of Denial of Service from crafted files.

  3. Operational

    Monitor systems running MP4Box for crashes, high resource usage, or DoS symptoms related to m2tsdmx_send_packet; if such behavior is observed, stop the service, capture the offending file(s) for analysis, and isolate the affected host for investigation.

Event History

Jun 1, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2025-55664?

The severity of CVE-2025-55664 is medium, rated at 5.5 on the CVSS scale.

2

How do I fix CVE-2025-55664?

To mitigate CVE-2025-55664, upgrade GPAC/MP4Box to the latest version where the vulnerability is patched.

3

What type of vulnerability is CVE-2025-55664?

CVE-2025-55664 is categorized as a heap-based buffer overflow.

4

What can attackers achieve with CVE-2025-55664?

Attackers can exploit CVE-2025-55664 to cause a Denial of Service (DoS) by supplying a crafted MPEG-2 TS file.

5

Which function is affected by CVE-2025-55664?

The m2tsdmx_send_packet function in GPAC MP4Box is affected by CVE-2025-55664.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203