CVE-2025-60467: Use-After-Fe in GPAC/MP4Box via gf_filter_pid_inst_swap_delete_task on crafted MPEG-2 TS file
Published Jun 24, 2026
·Updated
A use-after-free in the gffilterpidinstswapdeletetask function (/filtercore/filterpid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted media file.
Affected Software
2 affected components
Gpac MP4Box<26.02.0
Gpac GPAC<26.02.0
Remediation
Patch Available
Event History
Jun 24, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·11:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-60467?
The severity of CVE-2025-60467 is rated high with a CVSS score of 7.5.
2
How do I fix CVE-2025-60467?
You can fix CVE-2025-60467 by applying the available patch from the GPAC Project.
3
What type of vulnerability is CVE-2025-60467?
CVE-2025-60467 is categorized as a Use-After-Free vulnerability.
4
What could be the impact of CVE-2025-60467?
The impact of CVE-2025-60467 could result in a Denial of Service (DoS) when a crafted MPEG-2 TS file is supplied.
5
In which software is CVE-2025-60467 found?
CVE-2025-60467 is found in GPAC's MP4Box software.