CVE-2025-60464: NULL Pointer Defence in GPAC/MP4Box via gf_sei_load_from_state_internal on crafted MPEG-2 TS file
Published Jun 25, 2026
·Updated
A use-after-free in the gfseiloadfromstateinternal function (/filters/seiload.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MPEG-2 TS file.
Affected Software
2 affected components
GPAC/MP4Box<26.02.0
Gpac GPAC<26.02.0
Remediation
Patch Available
Event History
Jun 25, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-60464?
The severity of CVE-2025-60464 is classified as high with a CVSS score of 7.8.
2
What does CVE-2025-60464 affect?
CVE-2025-60464 affects the GPAC Project/MP4Box software, specifically through a vulnerability in the gf_sei_load_from_state_internal function.
3
How can I fix CVE-2025-60464?
The recommended fix for CVE-2025-60464 is to apply the available patch.
4
What type of vulnerability is CVE-2025-60464?
CVE-2025-60464 is categorized as a Use After Free vulnerability.
5
What is the risk associated with CVE-2025-60464?
CVE-2025-60464 has an associated risk rating of 72, indicating significant potential impact, including Denial of Service.