CVE-2025-60465: Use-After-Fe in GPAC/MP4Box via gf_filter_pid_inst_swap on crafted MPEG-2 TS file
Published Jun 25, 2026
·Updated
A use-after-free in the gffilterpidinstswap function (/filtercore/filterpid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.
Affected Software
2 affected components
Gpac MP4Box<26.02.0
Gpac GPAC<26.02.0
Remediation
Patch Available
Event History
Jun 25, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-60465?
The severity of CVE-2025-60465 is medium with a CVSS score of 6.1.
2
How do I fix CVE-2025-60465?
You can fix CVE-2025-60465 by applying the available patch provided by the GPAC Project.
3
What impact does CVE-2025-60465 have on software?
CVE-2025-60465 can lead to a Denial of Service (DoS) by exploiting a use-after-free vulnerability in GPAC/MP4Box.
4
Which function is affected by CVE-2025-60465?
CVE-2025-60465 affects the gf_filter_pid_inst_swap function in the filter_core/filter_pid.c file.
5
What kind of files can trigger CVE-2025-60465?
CVE-2025-60465 can be triggered by supplying a crafted MPEG-2 TS file.