CVE-2025-60466: Expid Pointer Defence in GPAC/MP4Box via gf_filter_pid_get_packet on crafted MPEG-2 TS file
Published Jun 24, 2026
·Updated
A use-after-free in the gffilterpidgetpacket function (/filtercore/filterpid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.
Affected Software
2 affected components
Gpac Project MP4Box<26.02.0
Gpac GPAC<26.02.0
Remediation
Patch Available
Event History
Jun 24, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jun 25, 2026
Data Sourced
via NVD·12:17 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-60466?
CVE-2025-60466 has a medium severity rating of 5 on the CVSS scale.
2
How does CVE-2025-60466 affect users?
CVE-2025-60466 allows attackers to exploit a use-after-free vulnerability leading to a Denial of Service (DoS) via a crafted media file.
3
What software is impacted by CVE-2025-60466?
CVE-2025-60466 affects the GPAC Project and its MP4Box software.
4
Is there a fix available for CVE-2025-60466?
Yes, a patch for CVE-2025-60466 is available.
5
What type of vulnerability is CVE-2025-60466?
CVE-2025-60466 is categorized as a use-after-free vulnerability.